• Resolved jmkt

    (@jmkt)


    We are getting many notifications of “attempted a failed login using an invalid username “admin””. This is happening to 3 of the 15 sites that we manage. We have reduced the login attempts to 5 and blocked IP addresses for 2 months. We have also blocked several ranges of IP address and several browser matches. So far there has been no real improvement as shortly afterwords we receive attempts from other IP addresses.

    Question – Other than being a pain in the *** is this like to cause any issues? Our username is never “admin” and our passwords are 10 to 12 randomly selected characters.

    Thanks in advance.

    https://www.ads-software.com/plugins/wordfence/

Viewing 4 replies - 1 through 4 (of 4 total)
  • I see repeated admin login attempts on my site also. As you have changed your username, use a strong password and are blocking repeated attempts from the same IP you should be very safe indeed. On point to bear in mind is that most IP addresses host hundreds of users, of which only one is usually causing issues by malicious login attempts. Therefore, I avoid blocking any one IP address for longer than 1 hour after 3 failed attempts if the IP address is from a country where I have a high number of visitors. This disrupts login attempts without permanently excluding the other genuine potential visitors using that IP address.

    Plugin Author Wordfence Security

    (@mmaunder)

    Hi,

    We are introducing a new feature in the next release that lets you define usernames where if a hacker tries to sign-in using one of the usernames, they will be immediately blocked.

    You can thank my co-founder Kerry for this – she literally mentioned that we need to get this feature in the next release less than an hour ago because many of our users are asking for it. It sounds like it will solve your problem.

    Regards,

    Mark.

    Confirmed. This feature will be in the next release.

    Thread Starter jmkt

    (@jmkt)

    Excellent.

    Will be a great help.

    Many thanks.

Viewing 4 replies - 1 through 4 (of 4 total)
  • The topic ‘Large Number of Failed Logins’ is closed to new replies.