Forum Replies Created

Viewing 5 replies - 1 through 5 (of 5 total)
  • It is unchecked. Always has been.

    OK. Now I understand better and see where my confusion came from. Thank you.

    BUT, I do not have a userid named “admin” yet the plugin is blocking those attempts that try to use “admin” as a userid. Why is this?

    My admin account did have “admin” set as both nickname and public display name (I have just changed it). BTW, I have never seen a login attempt on my actual login id (which is a random string).

    Thanks so much for your time, I’m finally understanding this better and seeing the errors in what I thought I understood before.

    Sorry Keith but I am confused.

    If you are not checking for “admin” user id, what on earth does “Blacklist login attempts using ‘admin’ userid:” mean? This is what we are talking about.

    And I don’t even see “check for admin” as an option! (Yes, I’m running version 5.5)

    Agreed. Multiple attacks in a short space of time on “Admin” getting passed and cached as good IPs seems quite silly.

    Thank you!

    The real user names are visible at the top of every page and post, right next to the date. Just mouse over the displayed name and look at the URL. It’s right there.

    There is a LOT of login attacks on wordpress sites this week, it does not necessarily mean that you have been recently compromised.

    BTW, login attacks like this will not only try “admin”, they will also use the name of the website too, so also avoid that choice, and any related names, for your admin username.

    To that end if you want to hide the admin user name, and ensure that current attacks can’t get in, don’t publish a post with admin as author. If you like, you can create another user account (as contributor, say, thus limited capabilities even if the account is compromised) and assign any posts previously published by the admin to that user.

    Then create a new user account with an unguessable user name and a secure password. Make it an administrator. Log in with that account and delete the original admin account. Any posts authored by that original admin account will be reassigned to an existing author (you get to choose which one).

    Of course if your passwords are strong you have little to worry about from login attacks. The attacks that I’m seeing are using a standard list of common weak passwords. With some time and thought, you can choose a very strong password that is easy to remember. It is very worrying when you see attacks try a real existing user name but if the password is strong, it doesn’t really matter.

Viewing 5 replies - 1 through 5 (of 5 total)