• Resolved bonedoctor

    (@bonedoctor)


    Hello,
    My website was attacked using the custom login URL, minutes after it was set up.

    I found the topic “Hackers finding custom login URL” and checked the page code source : in my case, the “secret” url was visible in the logout link of the Admin Bar.

    It is easy to disable the Admin Bar, but I think that it should be mentioned in the ‘Getting Started with WP Cerber’ page.

    Maybe there is a way to disable only the Admin Bar logout link (or hide it) ?

    using WordPress 4.9.9 + avada theme

Viewing 1 replies (of 1 total)
  • Plugin Author gioni

    (@gioni)

    Hi!

    First of all, having the login URL in the WordPress admin bar is normal. This is how it works by default. Secondly, the admin bar is not showing for non-logged in visitors. I do not recommend disabling the login link on the admin bar. You’re looking in the wrong direction. I think your custom login URL is displayed somewhere else in one of the menus or widgets so it’s visible for bots and accessible for hacker attacks.

Viewing 1 replies (of 1 total)
  • The topic ‘custom login URL visible in Admin Bar logout link and hacked’ is closed to new replies.