• gezafodor

    (@gezafodor)


    Hello,

    I have no more idea, what should I do to prevent our site from unwanted logins.

    Things that we have done:
    – there are neither standard wp-admin nor wp-login pages
    – there is no user with user name “admin”
    – Wordfence Plugin active
    – Wordfence Login Security plugin is active
    – XML-RPC authentication disabled
    – ReCaptcha v3 is active
    – all plugins are up to date

    Has anyone other suggestion? Other things that should be done?

    Thx.

    Geza

Viewing 2 replies - 1 through 2 (of 2 total)
  • wfdave

    (@wfdave)

    Hi @gezafodor,

    In the title you mentioned unwanted user registrations, but in the body you have unwanted logins, do you want to prevent both of these?

    In both cases, setting up recatpcha will prevent bots from automating registration/logins on your site.

    However, if you have humans creating and logging into accounts, that is harder to prevent. You can make your rate-limiting rules stricter, which will prevent the amount of requests a human can send in a specified interval.

    Dave

    Thread Starter gezafodor

    (@gezafodor)

    Hello @wfdave

    thank you for your reply. Th question is the unwanted registrations. I have today no idea, where is the form, what is the URL, that spammers are using for registrations. Maybe I could set up a firewall rule to prevent this path. As I mentioned above, I modified the admin URL, RPC access, everything I could, but see below, yesterday I got again a badass registration.

    Geza

    New User created account on your site New User Account Details are : Name: отличное крео для донора отличное крео для донора отличное крео для донора отличное крео для донора отличное крео для донора отличное крео для донора https://www.google.com отличное крео для донора отличное крео для донора отличное крео для донора отличное крео для донора отличное крео для донора отличное крео для донора https://www.google.com User Name:отличное крео для донора отличное крео для донора отличное крео для донора отличное крео для донора отличное крео для донора отличное крео для донора https://www.google.com Password:IPIN******Q85U User Email:okaz******il.ru

    • This reply was modified 5 years ago by gezafodor.
Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘How to prevent unwanted user registrations?’ is closed to new replies.