Brute force attack
-
For the past 72 hours, I’ve been under attack on my WordPress site. The attacker is using many different IPs to try to log in. So far the Limit Login Attempts plugin is keeping this individual or group out. I wanted to set the retry attempts allowed to zero, but the plugin wouldn’t allow me. I have the minutes allowed until retry set to 4,000 minutes and retries set to one, but it doesn’t matter. The attack is nonstop. My email is filling up with notices of login attempts every minute.
I finally removed the wp-login page for now by FTP.
I would welcome a two-step login process.
I think the hackers have finally found a way around this plugin, which seems to be the only good option out there for limiting login attempts.
Any suggestions would be appreciated.
- The topic ‘Brute force attack’ is closed to new replies.