1,023 blocked malicious login attempts. Who trying to steal my blog? Any advises?
-
My new blog growing up fast and I'm about the break the Alexa million and I discovered 1,023 blocked malicious login attempts today. I'm really got scared when I saw this number. I'm using WordPress, any advises?
-
There will definitely be cases out there like you described, Massimiliano. It's a wild world out there. We can only do so much to protect ourselves.
-
Honestly, I would strongly suggest to avoid blocking traffic on a geographic basis, these days you never know where traffic will come from and why.
User sitting in the building next to yours but accessing internet from a corporate network may appear as connecting from China.
Legit bot from services you are paying for may appear as crawling from Sweden, and other legit bot you don't even know about but which let you reach additional audience may appear as connecting from the other side of the world.
Blocking traffic is positively dangerous, the only case where I would consider it a good decision is when blocking blacklisted ips, and even this case I would suggest to secure the blacklist is updated regularly to avoid blocking false positive.
-
Eslam - Many great suggestions here of the things you can do right now to help you with these hack attempts. One thing I'd like to add is that we use a service/plugin called Sucuri. We've had good luck with it so far. You can learn more about them here: http://sucuri.net/
Regarding the approach of blocking traffic from other countries, my thought is this. Does traffic from those countries bring any value to you and do you give value to those visitors? If you answer no to this question, then why not block it? For example, a local pizza shop's website in Portland, Oregon probably doesn't care bout web traffic from Lithuania and vice versa.
-
Bulletproof Security is great and has many features to blocking such attempts and making it harder for those scripts that are just constantly scanning for the usual vulnerabilities.
-
theres a wordpress plugin you can use that limits the number of login attempts (I used to use it but I forgot the name of it)
-
Instructions here: https://wordpress.org/support/topic/how-to-change-from-wp-loginphp-to-login
-
It's won't type my password there really. I don't know ...
-
I don't think it's easy to change it because there PHP complicated things that I don't know about. But, I will search for a trusted plugin or something like that. Seems like a good solution.
-
I don't know, it's a very abuse thing to ban traffic from a country. If you are saying these attacks are automated so they are not humans?
-
I've. But, do you think it's enough. I'm talking about that I'm talking with you right now and there's someone right there trying to steal my thing. Hard feeling really.
-
I agree with Massimillano here.
Three things you should do for all common CMS systems (WP, Joomla, ect..)
First change the admin directory to something else. When doing this you likely have to edit configuration files to point to the new location which is pretty simple.
Second protect admin directory with .htaccess & .htpasswd. There is a nice generator I have used on some of my sites in the past here.
Third create a honeypot / auto IP ban for malicious crawlers or script kiddies. There are several plugins for this if you search the keywords honeypot + cms.
-
Change the name of the login page, I mean in addition to having a strong password of course.
Those automated scripts look first for the known wp login page if they don't find it the will give up, if they do they will keep trying forever and ever, an unecessary load for your servers.
-
This is a very common thing. Most of these attacks are automated, coming from China or Eastern Europe. You may consider banning traffic from those countries all together if it's not relevant to you. Change the default admin user name to something else. And do as EGOL recommended - set a really strong password. And then change that password every few months.
-
Make a really strong password.
Got a burning SEO question?
Subscribe to Moz Pro to gain full access to Q&A, answer questions, and ask your own.
Browse Questions
Explore more categories
-
Moz Tools
Chat with the community about the Moz tools.
-
SEO Tactics
Discuss the SEO process with fellow marketers
-
Community
Discuss industry events, jobs, and news!
-
Digital Marketing
Chat about tactics outside of SEO
-
Research & Trends
Dive into research and trends in the search industry.
-
Support
Connect on product support and feature requests.
Related Questions
-
Authorship showing in SERPs for non-blog pages
Hi, A few months ago we set up authorship for on our blog articles for multiple authors, which has helped driving extra traffic to our blog posts. Today, I did a search for one of most important search terms and one of our non-blog pages is showing in the first page of the results with one of our authors headshot next to it. Technically we have not not set it up to do this, the page is on a different CMS to our blog (which is wordpress). I'm not complaining because I think this is a positive outcome, but does anyone have an idea why it has done this? I was under the impression that only blog article pages could have authorship set up. Thanks, Stu
Content Development | | Stuart260 -
Blogs, blogspot, tumblr etc
We currently have our own wordpress blog on our site using wordpress, is it worth while having others such as blogspot, tumblr etc for seo purposes? Or would I be wasting my time and efforts?
Content Development | | Shuffled0 -
Name Some Ecommerce Sites That NAIL Blogging
Have a few favorites but would like to get some other people's opinions on some ecommerce sites that are doing blogging RIGHT. Who is supporting their online marketing with an amazing blog? One of my favorites is Backcountry.com's The Goat (http://thegoat.backcountry.com/) Let me know!
Content Development | | GManSEO1 -
Does Google penalize for duplicate blog posts?
Occasionally, I get asked by another blogger if they can repost (in full) one of our blog posts on their blog as a guest post. I've always been under the impression that Google penalizes this type of behavior, but I haven't seen any evidence. Is this true?
Content Development | | Event360300 -
3rd Party Commenting System for Wordpress Blog
I'll be starting a new blog within a week, for that i'm thinking to implement a 3rd party comment system instead of default wordpress comment system. I'm thinking of Livefyre or Facebook Comment System. Mostly my heart is saying to go for Livefyre. I'm in such a niche where i need more likes and sharing, so do you advice me to got for Facebook Commenting System. What do you guys suggest and recommend. which is better? Pls do advice, thanks 🙂
Content Development | | gurrambharath0 -
Promoting external blogs on our own
From time to time we're promoting blog posts written by our employees on their external blogs (separate domains) to our official company blog. This happens when the content is valuable for our visitors and it's worth to be shared. The post is copied in its entirety and we add the sentence This post was originally published on <external blog="" post="" link="">at the top. Will this be considered duplicate content? Should we add anything else to the republished blog post? Thanks!</external>
Content Development | | lgrozeva0 -
Opinions for the Long URL strings in WordPress Blogs.
We use Wordpress for our agency Blogs. The URL's are very long and the Moz does not like the long URL's. Should we use the stubby, short Wordpress URL's for each blog post? Is there a "Best Practice" for how one should use the Wordpress URL string?
Content Development | | theideapeople0 -
Best strategy for content/articles. Individual pages or blog posts?
Hi all, Whilst adding content to one of my sites quite often I'm left deciding whether I should create an individual webpage for the content, or write it up as another blog post. More often I write it up as a static page so it fits in with the rest of my website more 'directly'. However I'm wondering if I'm missing out here as obviously I'm not taking advantage of the benefits of a blog, RSS, Tag Cloud, etc etc... Just wondering if others encounter the same quandary?
Content Development | | davebrown19750