Can Login URL Be Determined While Using This Plugin?
-
One of my websites has been under sustained brute force attacks for a few days now. Whenever I block the IP the attacks are coming from, it starts again from a new address.
I tried activating this plugin in order to change the URL for both /wp-admin/ and /wp-login.php. After changing both to custom values, the attacks continued (logged with Sucuri).
I was expecting the attacks to stop once the login URL was changed, as the attacker shouldn’t even know where the admin portal is located, however they have continued unabated.
Do you know how this might still be happening? Is it possible for an attacker to “find” the new custom admin URL that I created?
- The topic ‘Can Login URL Be Determined While Using This Plugin?’ is closed to new replies.