|   |   |   | ||||
| Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. | 
|    | 
| 
 | |||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. | 
|  | Thread Tools | 
|  09-10-2015, 07:44 PM | #1 | 
| Confirmed User Industry Role:  Join Date: Nov 2011 Location: montreal 
					Posts: 589
				 | 
				
				Just got notifications of several log in attempts to my site as admin
			 I am getting a lot of notifications from these spammers 192.99.154.24 77.247.181.162 they are using TOR.. what should I do.. SO far 50 trials with different IPs all appear as blocked by google | 
|   |           | 
|  09-10-2015, 09:29 PM | #2 | 
| jscizzle Industry Role:  Join Date: Feb 2001 Location: Taipei 
					Posts: 25,198
				 | are they hitting your login.php page (wordpress) or some other login page? You can ask your host to password protect that login page. 
				__________________  “If you think tough men are dangerous, wait until you see what weak men are capable of.”  —Jordan B. Peterson Listen to Pomp tell why is Bitcoin important | 
|   |           | 
|  09-10-2015, 10:03 PM | #3 | 
| Confirmed User Industry Role:  Join Date: Jun 2003 Location: My High Horse 
					Posts: 6,334
				 | I get them at least once a day   I cant protect my login page because I have members that comment and that wouldnt really be conducive  The first thing you want to do is make sure that if the admin account exists  it doesnt have admin privileges  just ordinary ones that way if they do manage to brute force it it doesnt get them anything  if you have wordpress by all means run wordfence. there are some php and some apache stuff to weed out some proxies...google it if ya need more help hit me up via email 
				__________________ Mike South It's No wonder I took up drugs and alcohol, it's the only way I could dumb myself down enough to cope with the morons in this biz. | 
|   |           | 
|  09-10-2015, 11:55 PM | #4 | 
| Confirmed User Industry Role:  Join Date: Jun 2012 
					Posts: 457
				 | You can get a list of tor IP's here and block them; https://check.torproject.org/cgi-bin/TorBulkExitList.py The list is very dynamic though I pull a fresh my list every 15 mins. | 
|   |           | 
|  09-11-2015, 01:31 AM | #5 | 
| So Fucking Banned Industry Role:  Join Date: Apr 2003 Location: online 
					Posts: 8,766
				 | use wordpress plugins, like: captcha on wp-login and bruteprotect | 
|   |           | 
|  09-11-2015, 01:50 AM | #6 | |
| So Fucking Banned Industry Role:  Join Date: Jun 2010 Location: Tokyo Red Light District 
					Posts: 2,145
				 | Quote: 
 Get Word-Fence plug in or Fail2Ban Got our first from a TOR exit IP recently as well.  | |
|   |           | 
|  09-11-2015, 02:53 AM | #7 | 
| Confirmed User Industry Role:  Join Date: Nov 2011 Location: montreal 
					Posts: 589
				 | Hellog guys, thanks. I already have wordfence. Good idea about the admin privileges.  Mike, I will be contacting for sure if I need more guidance! thanks!! I used to get one or two every dat, but yesterday 50 different Ips (each was lock oit after 20 attempts) really made me wonder was going on | 
|   |           | 
|  09-11-2015, 12:53 PM | #8 | 
| Confirmed User Industry Role:  Join Date: Jan 2012 Location: NC 
					Posts: 7,683
				 | rename login.php to somethign else., 
				__________________ SSD Cloud Server, VPS Server, Simple Cloud Hosting | DigitalOcean | 
|   |           | 
|  09-11-2015, 01:17 PM | #9 | 
| Confirmed User Industry Role:  Join Date: Nov 2002 Location: FL - TN/NC 
					Posts: 5,211
				 | Step 1 is this. Never use defaults is always step 1 on an install, step 2 is to keep records of what you change them to. | 
|   |           | 
|  09-11-2015, 02:19 PM | #10 | 
| Confirmed User Join Date: May 2008 Location: Pennsylvania 
					Posts: 4,204
				 | I use wordfence and the user locker plugin.  User Locker automatically locks an account with too many failed login attempts, and it can't be restored unless another administrator removes the lock. Plus you can manually lock accounts, so the first thing I do is create "admin" to set up my wordpress, then create a different user name with administrator privileges; log into the new account, and lock and disable "admin." 
				__________________ Online strip gaming with sexy gamer girls Best thing I ever signed up for: Quality Razors, Cheap Price | 
|   |           | 
|  09-11-2015, 02:28 PM | #11 | 
| I'm a great bowler. Industry Role:  Join Date: Nov 2003 Location: Right Outside of Normal. 
					Posts: 13,309
				 | This.  Bury that mother fucker deep into some sub-directory.  99% of the time they don't do this shit manually.  They search for defaults and go from there.  If your login.php is located somewhere else, or you don't even have an admin directory, they'll go somewhere else. | 
|   |           | 
|  09-11-2015, 02:31 PM | #12 | 
| Promoting Debate on GFY Industry Role:  Join Date: Apr 2007 
					Posts: 27,176
				 |  
				__________________ | 
|   |           | 
|  09-11-2015, 02:51 PM | #13 | 
| Carpe Visio Industry Role:  Join Date: Jul 2002 Location: New York 
					Posts: 43,064
				 | I manage a blog for someone who creates Paleo cookbooks and is a NYT Best Seller. The blog gets about 75-100k visitors on any given day. I use WordFence and get notifications when people attempt to login. It happens all day long, 24/7. | 
|   |           | 
|  09-11-2015, 04:33 PM | #14 | 
| Confirmed User Industry Role:  Join Date: May 2010 
					Posts: 5,735
				 | I only allow my IP through to wp-login.php and deny everyone else so they can't even see the page let alone attempt to bruteforce. | 
|   |           |