WordPress site under attack
-
I have a WordPress site that is under attack.
I am using the limit login attempts plugin. So I get an email for every failed attempt. I have had about 30 attempts today each one using a different IP, about 30 mins apart (as my plugin is blocking that IP on a failed attempt).
I am using nginx and have made /wp-admin hidden so it returns forbidden.
I have also changed wp-login.php to wp-login.php_somethinghere
But for some reason its not stopping the attempts. My guess is that the hacker must be using a proxy server and posting directly to a file but which one? Any ideas?
Thanks!
IP list so far in case it helps in some way:
118.233.70.30
180.59.50.128
39.32.199.149
79.145.164.4
167.114.65.164
77.69.112.109
46.121.15.5
158.58.234.54
213.10.32.143
175.156.93.187
188.129.70.61
197.33.38.181
88.101.96.99
94.230.84.105
79.177.108.110
103.17.100.19
210.186.202.223
154.73.58.75
84.50.17.141
161.0.114.2
84.117.177.188
79.118.2.76
191.112.79.22
79.175.76.39
186.188.59.171
178.164.239.156
62.113.0.40
41.104.65.205
188.247.74.185
62.201.234.172
105.236.232.213
46.120.162.182
190.163.215.166
75.185.243.125
121.54.47.162
39.7.55.179
77.196.18.14
- The topic ‘WordPress site under attack’ is closed to new replies.