Immediately block the IP of users who try to sign in as these usernames
-
Hi. I use your plugin on several sites, and always like to enable the “Immediately block the IP of users who try to sign in as these usernames” feature to weed out a few of the most commonly used brute-force usernames. Normally, this works great. The list of usernames I am currently checking on this site is:
systemwpadmin,admin,administrator,test,user,root
Today, someone logged into a site using ‘systemwpadmin’ which Wordfence (and Sucuri) alerted me to. I know this is a known (yet mysterious) exploit that is mentioned a bit on Google (https://www.google.com/?gws_rd=ssl#q=wordpress+systemwpadmin) which is why I have that username in the block list to begin with. What I am confused about is how this was able to happen at all, if this username is in the “Immediately block” list ? It was obviously some sort of “normal” login routine since it triggered both alerts to me, so this seems really odd that it was allowed.
Any thoughts?
- The topic ‘Immediately block the IP of users who try to sign in as these usernames’ is closed to new replies.