Is Site Under Attack by Spoofed IPs or From Behind VPN?
-
I get scores of emails per day about IPs being blocked for too many attempts to break into the admin area of our site. What I notice is that while there might be 30 different IP addresses, the usernames might be the same or slight variations of a basic one. For example, I just noticed wadminw was associated with suposed tries from France, Holland and Germany, an almost impossible probability that three hackers in different countries decided on the same username (outside of the usual admin).
How effective is WordFence really if many of the IP addresses blocked are not those of the hackers but legitimate users who on an off chance might visit the site and find themselves locked out?
What also befuddles me is that while anyone attempting to access example.com/wp-admin is automatically sent to a 404 page, these many attempts st breaking in can still access the log-in URL.
Is there something to be fixed or corrected?
- The topic ‘Is Site Under Attack by Spoofed IPs or From Behind VPN?’ is closed to new replies.