Viewing 5 replies - 1 through 5 (of 5 total)
  • Thread Starter Olivia

    (@hipphooray88)

    UPDATE:

    I called my host and found out that my site had hacked and .htaccess was changed to redirect … my God! And, on top of it, AIO-WP Security Plugin was completely removed from my site !!!

    I saved the altered .htaccess if you want to take a look. But, I am stunned because I have 17 characters, numbers, plus symbols password.

    I am doing EVERYTHING I can to protect my site. What else can I do?

    Thread Starter Olivia

    (@hipphooray88)

    UPDATE:

    Sorry, it was DEACTIVATED, not removed …
    But, still so spooky.

    Plugin Contributor wpsolutions

    (@wpsolutions)

    I have been using this special URL to prevent the brute attacks. But, for some reason, it stopped working and my browser cannot find the wp-admin page. I would either get 127.0.0 or go to my blog page without the admin login

    Are you referring to the “Cookie Based Brute Force Prevention” feature or the “Rename Login Page” feature?

    With the little information you have provided it is difficult to say how your site apparently go hacked. There is more than one door from which someone can access your site.

    Our plugin does its best to protect your site from the WordPress point of view.

    But you also have FTP and CPANEL access and other routes which are not controlled or protected by our plugin.

    Thread Starter Olivia

    (@hipphooray88)

    Yes. Cookie basedBFP. Apparently the hacker got in back door, disabled the plug in and altered htaccess file. It’s not the plugin’s fault.

    The issue I have now is I cannot get that feature back on. So I installed another security plug in for now. I will need your help with that but my computer is not working and cannot get to the bottom of it now …

    I will have to get back with you on this in a few days if it’s ok. I’m typing this on my iPad and not so easy. Please keep the thread open. Thanks.

    Thread Starter Olivia

    (@hipphooray88)

    Hello,

    Just wasted to report that the Cookie Based BFP is working properly after refreshing the plugin a couple of times. So far, the rest seems to be working as well.

    The fact that the hacker went straight to the plugin and disabled it means that it is doing its job. I have tightened up the back door a bit better, so hoping that it is safer for now … but will need to consider other measure to protect the backdoor in near future.

    Thank you.

    I close this case …

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘Cannot go to the wp-admin page with the special url’ is closed to new replies.