• siriusly

    (@siriusly)


    Hi– I’m wondering how an obscure (but valid) — random character combo — admin username might have been found and attempted for login… I have Wordfence set to hide the admin username. I received this message:

    A user with IP address 119.18.60.5 has been locked out from the signing in or using the password recovery form for the following reason: Exceeded the maximum number of login failures which is: 5. The last username they tried to sign in with was: ‘<myactualadminusername>’
    User IP: 119.18.60.5
    User hostname: in6.hostgator.in

    Thanks!

    https://www.ads-software.com/plugins/wordfence/

Viewing 4 replies - 1 through 4 (of 4 total)
  • WFBrian

    (@wfbrian)

    Hello,

    Hackers are sneaky. Are all your themes and plugins up-to-date? Holes can be introduced there. You may want to create a new admin user and decommission the user that was discovered.

    -Brian

    Thread Starter siriusly

    (@siriusly)

    Thanks. Everything is up-to-date, and I’ve already decommissioned the admin user, of course. I’ve tried all of the usual suspects (looking for author ID, etc.), but haven’t been able to hack to find the admin username myself. Scans find no malware… Have a ticket in to the hosting company… have a feeling it’s on their end. The site is really just a testing site, so it’s not critical, but I’d like to know where the hole is anyway! Will report back if I find out.

    WFSupport

    (@wfsupport)

    Are any of the posts by the admin user (even the default Hello World post)? Check the author. Also check “uploaded by” tag on images/media. Easy to forget but also easy for a hacker to see.

    tim

    Thread Starter siriusly

    (@siriusly)

    Well, that was dopey… yes, posts were by admin user, and it showed up in source code, even though front end display is off.
    A theme problem, right?

    <header>
          <h1 class="entry-title">Hey — Where’d my toolbar go?</h1>
          <div class="subhead">
        <span class="postauthortop author vcard">
        <i class="icon-user"></i> by <a href="https://mysitename.com/author/adminusername/" class="fn" rel="author">D D</a> |</span>
Viewing 4 replies - 1 through 4 (of 4 total)
  • The topic ‘Admin username found – IP blocked’ is closed to new replies.