Security and hack attempts
-
I have a fairly new WordPress multisite with the Limit Login Attempts plugin and a Disable Users plugin. All of my sites are being bombarded by a login bot with a limitless supply of IP addresses (probably random).
The attacker has somehow been able to figure out my user ID even though it is, as far as I can tell from the profile settings, not visible. I tried disabling the login page, “wp-login.php”. But, I continued receiving lockout notices. So, I disabled the user ID. Yet, this leaves several security concerns.
- How did the attacker acquire my user ID?
- How is the bot still able to attempt logins while the login page is disabled or even removed entirely?
- Does the “Disable Users” plugin work through the login page? (if so, it is not effective and I will need to address it immediately.)
- Are any of these vulnerabilities related to WordPress multisite?
- Is there a more effective way to secure WordPress sites?
Direct answers to any of these questions will be greatly appreciated.
Viewing 5 replies - 1 through 5 (of 5 total)
Viewing 5 replies - 1 through 5 (of 5 total)
- The topic ‘Security and hack attempts’ is closed to new replies.