Login attack with NO user name
-
I am seeing a rash of brute force or dos attacks that are happening with no valid logins. Here is the message from wordfence.
A user with IP address 154.100.109.37 has been locked out from the signing in or using the password recovery form for the following reason: Used an invalid username ” to try to sign in.
User IP: 154.100.109.37I would expect this with the ‘admin’ user or a guressed user name but no login name? there is really no way to block it is there? I got the above message from wordfence via email and at 2 to 10 emails an hour, with 5 attempts before locing out, that means the server is being hit 10 to 50 time a minute with bogus logins – for the past 18 hours now…
Any thoughts on how to lock these attacks out better?
- The topic ‘Login attack with NO user name’ is closed to new replies.