Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 09-10-2015, 07:44 PM   #1
ravenazrael
Confirmed User
 
Industry Role:
Join Date: Nov 2011
Location: montreal
Posts: 588
Just got notifications of several log in attempts to my site as admin

I am getting a lot of notifications from these spammers
192.99.154.24
77.247.181.162

they are using TOR.. what should I do.. SO far 50 trials with different IPs all appear as blocked by google
ravenazrael is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-10-2015, 09:29 PM   #2
jscott
So Fucking Banned
 
Industry Role:
Join Date: Feb 2001
Location: Taipei
Posts: 25,198
are they hitting your login.php page (wordpress) or some other login page? You can ask your host to password protect that login page.
jscott is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-10-2015, 10:03 PM   #3
mikesouth
Confirmed User
 
mikesouth's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: My High Horse
Posts: 6,346
I get them at least once a day I cant protect my login page because I have members that comment and that wouldnt really be conducive The first thing you want to do is make sure that if the admin account exists it doesnt have admin privileges just ordinary ones that way if they do manage to brute force it it doesnt get them anything if you have wordpress by all means run wordfence.

there are some php and some apache stuff to weed out some proxies...google it


if ya need more help hit me up via email
__________________
Mike South

It's No wonder I took up drugs and alcohol, it's the only way I could dumb myself down enough to cope with the morons in this biz.
mikesouth is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-10-2015, 11:55 PM   #4
Paz
Confirmed User
 
Paz's Avatar
 
Industry Role:
Join Date: Jun 2012
Posts: 457
You can get a list of tor IP's here and block them;
https://check.torproject.org/cgi-bin/TorBulkExitList.py

The list is very dynamic though I pull a fresh my list every 15 mins.
Paz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-11-2015, 01:31 AM   #5
klinton
So Fucking Banned
 
Industry Role:
Join Date: Apr 2003
Location: online
Posts: 8,766
use wordpress plugins, like: captcha on wp-login and bruteprotect
klinton is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-11-2015, 01:50 AM   #6
JuicyBunny
So Fucking Banned
 
Industry Role:
Join Date: Jun 2010
Location: Tokyo Red Light District
Posts: 2,145
Quote:
Originally Posted by ravenazrael View Post
I am getting a lot of notifications from these spammers
192.99.154.24
77.247.181.162

they are using TOR.. what should I do.. SO far 50 trials with different IPs all appear as blocked by google
Familiar IPs. We get a lot from UA, CN, KR, HK and ID cause of the content.
Get Word-Fence plug in or Fail2Ban

Got our first from a TOR exit IP recently as well.
JuicyBunny is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-11-2015, 02:53 AM   #7
ravenazrael
Confirmed User
 
Industry Role:
Join Date: Nov 2011
Location: montreal
Posts: 588
Hellog guys, thanks. I already have wordfence. Good idea about the admin privileges.
Mike, I will be contacting for sure if I need more guidance! thanks!!

I used to get one or two every dat, but yesterday 50 different Ips (each was lock oit after 20 attempts) really made me wonder was going on
ravenazrael is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-11-2015, 12:53 PM   #8
freecartoonporn
Confirmed User
 
freecartoonporn's Avatar
 
Industry Role:
Join Date: Jan 2012
Location: NC
Posts: 7,683
rename login.php to somethign else.,
freecartoonporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-11-2015, 01:17 PM   #9
suesheboy
Confirmed User
 
suesheboy's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: FL - TN/NC
Posts: 5,211
Quote:
Originally Posted by freecartoonporn View Post
rename login.php to somethign else.,
Step 1 is this.

Never use defaults is always step 1 on an install, step 2 is to keep records of what you change them to.
suesheboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-11-2015, 02:19 PM   #10
NaughtyVisions
Confirmed User
 
NaughtyVisions's Avatar
 
Join Date: May 2008
Location: Pennsylvania
Posts: 4,204
I use wordfence and the user locker plugin. User Locker automatically locks an account with too many failed login attempts, and it can't be restored unless another administrator removes the lock.

Plus you can manually lock accounts, so the first thing I do is create "admin" to set up my wordpress, then create a different user name with administrator privileges; log into the new account, and lock and disable "admin."
__________________
Online strip gaming with sexy gamer girls
Best thing I ever signed up for: Quality Razors, Cheap Price
NaughtyVisions is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-11-2015, 02:28 PM   #11
Rob
I'm a great bowler.
 
Rob's Avatar
 
Industry Role:
Join Date: Nov 2003
Location: Right Outside of Normal.
Posts: 13,310
Quote:
Originally Posted by freecartoonporn View Post
rename login.php to somethign else.,
This. Bury that mother fucker deep into some sub-directory. 99% of the time they don't do this shit manually. They search for defaults and go from there. If your login.php is located somewhere else, or you don't even have an admin directory, they'll go somewhere else.
Rob is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-11-2015, 02:31 PM   #12
wehateporn
Promoting Debate on GFY
 
wehateporn's Avatar
 
Industry Role:
Join Date: Apr 2007
Posts: 27,173
__________________
wehateporn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-11-2015, 02:51 PM   #13
candyflip
Carpe Visio
 
candyflip's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: New York
Posts: 43,052
I manage a blog for someone who creates Paleo cookbooks and is a NYT Best Seller. The blog gets about 75-100k visitors on any given day.

I use WordFence and get notifications when people attempt to login. It happens all day long, 24/7.
__________________

Spend you some brain.
Email Me
candyflip is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-11-2015, 04:33 PM   #14
anexsia
Confirmed User
 
anexsia's Avatar
 
Industry Role:
Join Date: May 2010
Posts: 5,735
I only allow my IP through to wp-login.php and deny everyone else so they can't even see the page let alone attempt to bruteforce.
anexsia is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
notifications, tor, trials, blocked, ips, google, spammers, site, attempts, log, admin, 192.99.154.24, lot, 77.247.181.162
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.