Dictionary attack
I installed this plugin this week, and it has been very effective in blocking comment spam. So far so good.
Yesterday, I noticed the blocked count had shot up by over 400. On closer inspection they were coming from one IP in Russia. The log cache showed that it was guessing admin passwords.
My question is this: is this expected behaviour? I expected the hacker to be blocked, but appeared to be very persistent. Does the log entry show that it was being blocked, and if so, why was it still trying?
It unnerved me so much, I added the IP to my htaccess block list.
