Hidden URL gets revealed by hitting wp-register.php
-
In my server logs I found a bot hitting my hidden login URL.
At first I was stupified: how could a (Russian) bot guess my secret login slug?I found out that the bot hitting https://www.mywebsite.com/wp-register.php
got redirected to https://www.mywebsite.com/secret-slug?action=register, which,
by the way, got redirected to https://www.mywebsite.com/secret-slug/?registration=disabledIs this a bug? Is this general behaviour?
Maybe you can fix this?I fixed it in htaccess by denying access to wp-register.php, which,
strangely enough, isn’t a proper wordpress-file.
Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
- The topic ‘Hidden URL gets revealed by hitting wp-register.php’ is closed to new replies.