Brute Force Amplification Attacks on my site
-
Hi
I am using wordfence for a long time.
I noticed in “Live activity” tab of wordfence many entries like this:
USER in State, States attempted a failed login as USER. https://mywebsite.com/xmlrpc.phpthe thing that bothers me the most is
1. how can an attacker discover my real USER?(it is indicated in the Live activity log)
these options are marked in wordfence:
Don’t let WordPress reveal valid users in login errors
Prevent discovery of usernames through ‘/?author=N’ scans
2. can changing wp-admin URL help?
Viewing 4 replies - 1 through 4 (of 4 total)
Viewing 4 replies - 1 through 4 (of 4 total)
- The topic ‘Brute Force Amplification Attacks on my site’ is closed to new replies.