2
I installed the Wordfence plugin and every day I get hacker attack report to wp-admin/site dashboard.
I decided to change the admin address with the plugin Protect WP-Admin, like this: site.com.br/Cmr21vnw, it seems to me impossible to find this address but keeps coming alerts of access attempts, less alerts but keeps coming.
Is there any way to try to log in via URL? How was the new address discovered? How to prevent this?
Thank you for your attention.
This is normal. Today and today there are attack robots running around the web looking for vulnerabilities to exploit.
– Augusto Vasques
That’s why your password has to be very strong. Special characters, uppercase letters, etc.
– Fabiano Monteiro
Actually by the report that Wordfence presents it seems to me that it is not something manual even, but I can not understand how the "robot" found the login folder that was renamed.
– Ed Dias
See if your server publishes help files to search engines. Type
sitemap
orrobot.txt
. Ex: https://www.google.com/robots.txt– Augusto Vasques
My robots.txt looks like this: User-agent: * Disallow: /wp-content Allow: /wp-content/uploads Disallow: /wp-admin .
– Ed Dias
Somehow the structure is being published. Take a look at if it has activity at port TCP 389. Another thing, I read that you use dynamic IP, you also use Dynamic DNS? Some DDNS’s force publishing directory structure.
– Augusto Vasques
I do not use dynamic DNS my host is Locaweb, only my connection IP is dynamic. Actually as I said "somehow the structure is being published".The plugin I used does not change the name of the wp-admin folder within the host but only the url, if you type wp-admin or even domain.com.br//wp-login.php does not open the login form. It seems to me that it is a direct attack without trying to access the form, I just don’t know which address is used because alerts of access attempts keep coming. It would be better to really change the name of the folder on the host, maybe it worked better but do not know Wordpress accepts this change.
– Ed Dias
Actually in Wordpress you can not change the path of the wp-admin folder only the url. Anyway look for data traffic on TCP port 389 this port is standard on all OS for publishing distributed directory services.
– Augusto Vasques