• Resolved Majklas

    (@majklas)


    I’ve just installed this plugin. Hit create backup (luckily had from wp-backup plugin) and nothing happened-no email at admin email, just new buttons with “secure from basic attacks”. I changed strong password authentication to editor from admin and then I hit save button. Strange things then heppened, I was logged out, red baloon in wp login aread was empty and wp-admin nor wp-login.php no longer worked.. Any ideas?

    http://wordpress.org/extend/plugins/better-wp-security/

Viewing 5 replies - 16 through 20 (of 20 total)
  • I doubt that this was the plugin., More likely it was your hosts that changed the file’s name after the recent worldwide brute force attacks.

    Thread Starter Majklas

    (@majklas)

    esmi, You’re right, maybe it was my admin. He won’t leave unpunished 🙂

    Handoko

    (@handoko-zhang)

    Interesting. I’ve been monitoring this forum more than a year. You perhaps are the first one that have such case. I agree with what esmi said. I’m sorry to hear such misfortune happened on you.

    Anyway, glad to know you can sleep sound tonight.

    I’ve seen quite a few hosts doing this and, frankly, I think it’s a rather clumsy attempt to circumvent brute force attack issues. My guess is that the attackers will simply try common variants of wp-login.php. You’d better off renaming the file back & looking at Brute Force Attacks which contains a number of better solutions.

    Handoko

    (@handoko-zhang)

    Renaming the file for avoiding brute force attack is okay for me personally, but what I think not okay is why don’t they inform their clients about the renaming. Bad, very bad.

Viewing 5 replies - 16 through 20 (of 20 total)

The topic ‘default admin login page?’ is closed to new replies.