The Moz Q&A Forum

    • Forum
    • Questions
    • My Q&A
    • Users
    • Ask the Community

    Welcome to the Q&A Forum

    Browse the forum for helpful insights and fresh discussions about all things SEO.

    1. SEO and Digital Marketing Q&A Forum
    2. Categories
    3. Content & Blogging
    4. 1,023 blocked malicious login attempts. Who trying to steal my blog? Any advises?

    1,023 blocked malicious login attempts. Who trying to steal my blog? Any advises?

    Content & Blogging
    15 7 10.1k
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as question
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Eslam-yosef
      Eslam-yosef last edited by

      My new blog growing up fast and I'm about the break the Alexa million and I discovered 1,023 blocked malicious login attempts today. I'm really got scared when I saw this number. I'm using WordPress, any advises?

      1 Reply Last reply Reply Quote 0
      • EGOL
        EGOL last edited by

        Make a really strong password.

        Eslam-yosef 1 Reply Last reply Reply Quote 1
        • VicMarcusNWI
          VicMarcusNWI last edited by

          This is a very common thing. Most of these attacks are automated, coming from China or Eastern Europe. You may consider banning traffic from those countries all together if it's not relevant to you. Change the default admin user name to something else. And do as EGOL recommended - set a really strong password. And then change that password every few months.

          Eslam-yosef 1 Reply Last reply Reply Quote 2
          • max.favilli
            max.favilli last edited by

            Change the name of the login page, I mean in addition to having a strong password of course.

            Those automated scripts look first for the known wp login page if they don't find it the will give up, if they do they will keep trying forever and ever, an unecessary load for your servers.

            Eslam-yosef 1 Reply Last reply Reply Quote 4
            • donford
              donford last edited by

              I agree with Massimillano here.

              Three things you should do for all common CMS systems (WP, Joomla, ect..)

              First change the admin directory to something else. When doing this you likely have to edit configuration files to point to the new location which is pretty simple.

              Second protect admin directory with .htaccess & .htpasswd.  There is a nice generator I have used on some of my sites in the past here.

              Third create a honeypot / auto IP ban for malicious crawlers or script kiddies. There are several plugins for this if you search the keywords honeypot + cms.

              Eslam-yosef 1 Reply Last reply Reply Quote 3
              • Eslam-yosef
                Eslam-yosef @EGOL last edited by

                I've. But, do you think it's enough. I'm talking about that I'm talking with you right now and there's someone right there trying to steal my thing. Hard feeling really.

                1 Reply Last reply Reply Quote 0
                • Eslam-yosef
                  Eslam-yosef @VicMarcusNWI last edited by

                  I don't know, it's a very abuse thing to ban traffic from a country. If you are saying these attacks are automated so they are not humans?

                  VicMarcusNWI 1 Reply Last reply Reply Quote 0
                  • Eslam-yosef
                    Eslam-yosef @max.favilli last edited by

                    I don't think it's easy to change it because there PHP complicated things that I don't know about. But, I will search for a trusted plugin or something like that. Seems like a good solution.

                    max.favilli 1 Reply Last reply Reply Quote 0
                    • Eslam-yosef
                      Eslam-yosef @donford last edited by

                      It's won't type my password there really. I don't know ...

                      1 Reply Last reply Reply Quote 0
                      • max.favilli
                        max.favilli @Eslam-yosef last edited by

                        Instructions here: https://wordpress.org/support/topic/how-to-change-from-wp-loginphp-to-login

                        1 Reply Last reply Reply Quote 0
                        • aap82
                          aap82 last edited by

                          theres a wordpress plugin you can use that limits the number of login attempts (I used to use it but I forgot the name of it)

                          1 Reply Last reply Reply Quote 0
                          • ScottOlson
                            ScottOlson last edited by

                            Bulletproof Security is great and has many features to blocking such attempts and making it harder for those scripts that are just constantly scanning for the usual vulnerabilities.

                            1 Reply Last reply Reply Quote 0
                            • VicMarcusNWI
                              VicMarcusNWI @Eslam-yosef last edited by

                              Eslam - Many great suggestions here of the things you can do right now to help you with these hack attempts. One thing I'd like to add is that we use a service/plugin called Sucuri. We've had good luck with it so far. You can learn more about them here: http://sucuri.net/

                              Regarding the approach of blocking traffic from other countries, my thought is this. Does traffic from those countries bring any value to you and do you give value to those visitors? If you answer no to this question, then why not block it? For example, a local pizza shop's website in Portland, Oregon probably doesn't care bout web traffic from Lithuania and vice versa.

                              max.favilli 1 Reply Last reply Reply Quote 0
                              • max.favilli
                                max.favilli @VicMarcusNWI last edited by

                                Honestly, I would strongly suggest to avoid blocking traffic on a geographic basis, these days you never know where traffic will come from and why.

                                User sitting in the building next to yours but accessing internet from a corporate network may appear as connecting from China.

                                Legit bot from services you are paying for may appear as crawling from Sweden, and other legit bot you don't even know about but which let you reach additional audience may appear as connecting from the other side of the world.

                                Blocking traffic is positively dangerous, the only case where I would consider it a good decision is when blocking blacklisted ips, and even this case I would suggest to secure the blacklist is updated regularly to avoid blocking false positive.

                                VicMarcusNWI 1 Reply Last reply Reply Quote 1
                                • VicMarcusNWI
                                  VicMarcusNWI @max.favilli last edited by

                                  There will definitely be cases out there like you described, Massimiliano. It's a wild world out there. We can only do so much to protect ourselves.

                                  1 Reply Last reply Reply Quote 0
                                  • 1 / 1
                                  • First post
                                    Last post
                                  • Blogging , do I create a huge blog which links to all my sites
                                    NickW816
                                    NickW816
                                    1
                                    2
                                    44

                                  • Blog.website.com or website.com/blog
                                    EGOL
                                    EGOL
                                    0
                                    5
                                    671

                                  • Global Blogs vs Regionalised blogs
                                    katemorris
                                    katemorris
                                    0
                                    4
                                    102

                                  • Move blogspot blog Domain/Blog
                                    EGOL
                                    EGOL
                                    0
                                    4
                                    172

                                  • Guest blog better than owned blog?
                                    ThompsonPaul
                                    ThompsonPaul
                                    0
                                    7
                                    203

                                  • Are there quality blog sites allowing guest blogging ?
                                    MoosaHemani
                                    MoosaHemani
                                    0
                                    4
                                    575

                                  • Onsite Blogging Vs Guest Blogging
                                    ClarityVentures
                                    ClarityVentures
                                    1
                                    4
                                    478

                                  • Why does my lousy little blog Rank number 1 on Google?
                                    slobodannn
                                    slobodannn
                                    0
                                    11
                                    785

                                  Get started with Moz Pro!

                                  Unlock the power of advanced SEO tools and data-driven insights.

                                  Start my free trial
                                  Products
                                  • Moz Pro
                                  • Moz Local
                                  • Moz API
                                  • Moz Data
                                  • STAT
                                  • Product Updates
                                  Moz Solutions
                                  • SMB Solutions
                                  • Agency Solutions
                                  • Enterprise Solutions
                                  • Digital Marketers
                                  Free SEO Tools
                                  • Domain Authority Checker
                                  • Link Explorer
                                  • Keyword Explorer
                                  • Competitive Research
                                  • Brand Authority Checker
                                  • Local Citation Checker
                                  • MozBar Extension
                                  • MozCast
                                  Resources
                                  • Blog
                                  • SEO Learning Center
                                  • Help Hub
                                  • Beginner's Guide to SEO
                                  • How-to Guides
                                  • Moz Academy
                                  • API Docs
                                  About Moz
                                  • About
                                  • Team
                                  • Careers
                                  • Contact
                                  Why Moz
                                  • Case Studies
                                  • Testimonials
                                  Get Involved
                                  • Become an Affiliate
                                  • MozCon
                                  • Webinars
                                  • Practical Marketer Series
                                  • MozPod
                                  Connect with us

                                  Contact the Help team

                                  Join our newsletter
                                  Moz logo
                                  © 2021 - 2026 SEOMoz, Inc., a Ziff Davis company. All rights reserved. Moz is a registered trademark of SEOMoz, Inc.
                                  • Accessibility
                                  • Terms of Use
                                  • Privacy