1,023 blocked malicious login attempts. Who trying to steal my blog? Any advises?
-
My new blog growing up fast and I'm about the break the Alexa million and I discovered 1,023 blocked malicious login attempts today. I'm really got scared when I saw this number. I'm using WordPress, any advises?
-
There will definitely be cases out there like you described, Massimiliano. It's a wild world out there. We can only do so much to protect ourselves.
-
Honestly, I would strongly suggest to avoid blocking traffic on a geographic basis, these days you never know where traffic will come from and why.
User sitting in the building next to yours but accessing internet from a corporate network may appear as connecting from China.
Legit bot from services you are paying for may appear as crawling from Sweden, and other legit bot you don't even know about but which let you reach additional audience may appear as connecting from the other side of the world.
Blocking traffic is positively dangerous, the only case where I would consider it a good decision is when blocking blacklisted ips, and even this case I would suggest to secure the blacklist is updated regularly to avoid blocking false positive.
-
Eslam - Many great suggestions here of the things you can do right now to help you with these hack attempts. One thing I'd like to add is that we use a service/plugin called Sucuri. We've had good luck with it so far. You can learn more about them here: http://sucuri.net/
Regarding the approach of blocking traffic from other countries, my thought is this. Does traffic from those countries bring any value to you and do you give value to those visitors? If you answer no to this question, then why not block it? For example, a local pizza shop's website in Portland, Oregon probably doesn't care bout web traffic from Lithuania and vice versa.
-
Bulletproof Security is great and has many features to blocking such attempts and making it harder for those scripts that are just constantly scanning for the usual vulnerabilities.
-
theres a wordpress plugin you can use that limits the number of login attempts (I used to use it but I forgot the name of it)
-
Instructions here: https://wordpress.org/support/topic/how-to-change-from-wp-loginphp-to-login
-
It's won't type my password there really. I don't know ...
-
I don't think it's easy to change it because there PHP complicated things that I don't know about. But, I will search for a trusted plugin or something like that. Seems like a good solution.
-
I don't know, it's a very abuse thing to ban traffic from a country. If you are saying these attacks are automated so they are not humans?
-
I've. But, do you think it's enough. I'm talking about that I'm talking with you right now and there's someone right there trying to steal my thing. Hard feeling really.
-
I agree with Massimillano here.
Three things you should do for all common CMS systems (WP, Joomla, ect..)
First change the admin directory to something else. When doing this you likely have to edit configuration files to point to the new location which is pretty simple.
Second protect admin directory with .htaccess & .htpasswd. There is a nice generator I have used on some of my sites in the past here.
Third create a honeypot / auto IP ban for malicious crawlers or script kiddies. There are several plugins for this if you search the keywords honeypot + cms.
-
Change the name of the login page, I mean in addition to having a strong password of course.
Those automated scripts look first for the known wp login page if they don't find it the will give up, if they do they will keep trying forever and ever, an unecessary load for your servers.
-
This is a very common thing. Most of these attacks are automated, coming from China or Eastern Europe. You may consider banning traffic from those countries all together if it's not relevant to you. Change the default admin user name to something else. And do as EGOL recommended - set a really strong password. And then change that password every few months.
-
Make a really strong password.
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
Blog.website.com or website.com/blog
Hello, I have a question, in some moz guidelines you can read website.com/blog is better/more recommended than blog.website.com. But when you look at the domain authority you see no difference. blog.website.com gets exact the same domain authority as website.com. So can somebody explain why website.com/blog is really better than blog.website.com? Or is there no difference? Thank you verry much
Content Development | | mystorenl0 -
URL Structure for Blog
Hi guys, Hope you are all doing well today. I have a questions with regards to our blog URL structure. The URL for the blog is /blog - however when you click on a blog post the "/blog" disappears completely and is replaced by the title of the post. So it is ".com/title-of-post" for example. Would it be better to keep the blog subdomain in the URL so it is ".com/blog/title-of-article" Any insight would be appreciated. My thoughts are that surely the second option above is ideal? Thanks Tom
Content Development | | National-Homebuyers0 -
Best places to get pictures for blog posts?
Well I'm really sick of reading people questions saying "help my sites been affected by penguin" So I thought I would ask something about blogging, where is the best place to find and buy pictures for blog posts? I already use Wikimedia commons. But I'm interested websites that have a bigger range that aren't too pricey. What do you recommend?
Content Development | | charles10 -
Guest Blogging Question
Hi Everyone, Bit of a serious question here for me, Is it worth doing a guest post on a blog more then 2 times? As an example one blog I guest post on has a homepage PR6 which I have posted 2 times, now they have requested another guest post but im thinking would it just be better to guest post on a different blog? So my question in simple terms is: 5 guest posts on two PR6 websites or 10 guest posts on ten different blogs with PR3
Content Development | | activitysuper0 -
Second Blog on the Same Site? Best SEO Practice
I would like to start up another blog which has more of a "technical" topic coverage vs my regular blog, which appeals more to non-techie business folks. If the goal is to drive traffic ultimately to the main site, should I do this second blog on a different domain, a subdomain, or try to incorporate it as a separate-but-equal blog on the same domain as the currrent one? What would you do?
Content Development | | JMagary0 -
Optimising my ecommerce blog
Hey guys, I am after suggestions on how i can better optimise my blog? www.imrubbish.co.uk/blog I have been getting regular blog posts up until say a month ago. Looking to get a new writer and get 3-4 blog posts a week done. Sometimes targeting products, sometimes general chat about bins. I am hoping you kind people can make a couple of suggestions i could be doing. Thank you
Content Development | | imrubbish0 -
How to Integrate a Wordpress Blog into my Website
We are looking at integrating a blog into our website. Unfortunately, our content management system is very clunky and not set up to quickly publish blog style content. I'd like to use Wordpress and set up the blog as a subdomain of my company website. Our URL is www.blockandcompany.com so the blog URL would be www.blog.blockandcompany.com. Is it correct to say that if the blog is set up this way, the search engines will see the regular website and the Wordpress hosted blog as one big site? I want to use the blog to write keyword-rich content, but I don't want to divide my SEO "equity" between two separate sites. Any advice?
Content Development | | Blockinc1 -
Transfer existing blog to wordpress.org or start a new blog
My blog sits on the wordpress domain http://gardenbeet.wordpress.com/ - it has good page rank and has around 300-400 visits per day - should i move it to my website or Should I start a new blog? i have a page set up for it on my website but it now has good rank http://www.gardenbeet.com/content/design-blog.html - and now want to keep this URL am a bit confused - what is the best strategy in terms of SEO?
Content Development | | GardenBeet1