Fun with Bots
-
Just a friendly suggestion from a heavy WF user.
I noticed I was being attacked by bots on various URLs for the file setup-config.php so I set up a honey trap using the “Immediately Block URL” in Wordfence Options.
As far as I can tell from reading WordPress Codex, setup-config.php is only used for new WordPress installs, it’s thus what I’d call vestigial (and incidentally is an example of another aspect of WordPress that unnecessarily attracts bots and uses up bandwidth.)
Setup-config.php exists in most WordPress installs as /wp-admin/setup-config.php, so for the most effective honey trap FTP into your WordPress install /wp-admin/ folder and rename the pesky bot attractor to something like /wp-admin/setup-config-renamed0986789.php then add the following to your Wordfence “Immediately Block URLs” and watch the fun via your Wordfence “Blocked” list. (The attacks I’m getting include URLs with more folders-directories than just one, so following has up to three steps to catch all the attacks).
/*/setup-config.php
/*/*/setup-config.php
/*/*/*/setup-config.phpRemember that due to the way Wordfence works, if a URL for a file exists the “Block URL” won’t function. Hence, the renaming of setup-config.php.
- The topic ‘Fun with Bots’ is closed to new replies.