Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-19-2017, 12:11 PM   #1
Bladewire
StraightBro
 
Bladewire's Avatar
 
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,229
When they try to crack your WP pw daily and think you don't know

You know we're just creating a list of your IP's to honeytrap right?

What do you guys do when you see this?
Bladewire is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-19-2017, 12:29 PM   #2
awxm
Confirmed User
 
Industry Role:
Join Date: Aug 2009
Posts: 819
Use a limit login attempt plugin or hide your wp-login.php/wp-admin or both. Not really anything to worry about as long as you use a strong pass and keep everything updated. It's more a nuisance screwing up server logs.

You can pentest your own site with WPScan and see what info your site is leaking i.e plugin/user enumeration
awxm is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-19-2017, 12:56 PM   #3
Markul
Likes Pie
 
Markul's Avatar
 
Industry Role:
Join Date: Dec 2007
Location: The land that liberated porn
Posts: 12,401
WP fence
Markul is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-19-2017, 01:09 PM   #4
Miguel T
♦ Web Developer ♦
 
Miguel T's Avatar
 
Industry Role:
Join Date: May 2005
Location: Full-Stack Developer
Posts: 12,470
All my wp-login / wp-admin/* is behind htaccess.
Then, if multiple attemps are failed, CSF takes care of blocking in iptables.
__________________

Full Stack Webdeveloper: HTML5/CSS3, jQuery, AJAX, ElevatedX, NATS, MechBunny, Wordpress
Miguel T is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-19-2017, 02:51 PM   #5
Bladewire
StraightBro
 
Bladewire's Avatar
 
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,229
Quote:
Originally Posted by Zuzana Miguel View Post
All my wp-login / wp-admin/* is behind htaccess.
Then, if multiple attemps are failed, CSF takes care of blocking in iptables.
After so many failed attempts mine are documented and blocked, then they come back 24 hours later with new IP's
Bladewire is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-19-2017, 08:18 PM   #6
JuicyBunny
So Fucking Banned
 
Industry Role:
Join Date: Jun 2010
Location: Tokyo Red Light District
Posts: 2,145
Quote:
Originally Posted by Bladewire View Post
After so many failed attempts mine are documented and blocked, then they come back 24 hours later with new IP's
Boot them for longer periods of time.

I think some of their intent is to have sites labeled as spammy to the SE's. You know, artificially inflating bounce rates. We found some that are hitting page after page of non-existent users, non-existent pages.

One was interesting though. They placed their affiliate code for a program we promote, to one of our domains and kept searching for that link. It was easy to find out who they are and report to SE's. 'The Google', lol, hates serp manipulators.

Current wave is being blamed on compromised routers. Do you agree?
JuicyBunny is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-19-2017, 09:03 PM   #7
Miguel T
♦ Web Developer ♦
 
Miguel T's Avatar
 
Industry Role:
Join Date: May 2005
Location: Full-Stack Developer
Posts: 12,470
Quote:
Originally Posted by Bladewire View Post
After so many failed attempts mine are documented and blocked, then they come back 24 hours later with new IP's
Make wp-login and wp-admin folder, IP restricted

This is what I had to do on a few feeder blogs of mine. They kept getting hit by bruteforce attacks and comments spammers.
__________________

Full Stack Webdeveloper: HTML5/CSS3, jQuery, AJAX, ElevatedX, NATS, MechBunny, Wordpress
Miguel T is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-19-2017, 09:16 PM   #8
JuicyBunny
So Fucking Banned
 
Industry Role:
Join Date: Jun 2010
Location: Tokyo Red Light District
Posts: 2,145
Quote:
Originally Posted by Zuzana Miguel View Post
Make wp-login and wp-admin folder, IP restricted

This is what I had to do on a few feeder blogs of mine. They kept getting hit by bruteforce attacks and comments spammers.
Smart answer. Asking host to do this now. If I could give you board rep I would!
JuicyBunny is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-19-2017, 09:18 PM   #9
Matt 26z
So Fucking Banned
 
Industry Role:
Join Date: Apr 2002
Location: ¤ª"˜¨๑۩۞۩๑¨˜"ª¤
Posts: 18,481
I'll get in eventually.
Matt 26z is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-19-2017, 09:26 PM   #10
Bladewire
StraightBro
 
Bladewire's Avatar
 
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,229
Quote:
Originally Posted by Zuzana Miguel View Post
Make wp-login and wp-admin folder, IP restricted

This is what I had to do on a few feeder blogs of mine. They kept getting hit by bruteforce attacks and comments spammers.
Thanks for the tip

We're documenting their IP's and regulating how many times they can attempt login everyday. It's a side curiosity and when I get more time to go through the data I'll share it.

Thanks again
__________________


Skype: CallTomNow

Bladewire is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-19-2017, 09:33 PM   #11
dillfly2000
hey
 
dillfly2000's Avatar
 
Industry Role:
Join Date: Mar 2012
Location: with you
Posts: 2,209
Yeah people are bastards, sight unseen, they don't think they're doing anything wrong. They usually just use the excuse "I'm testing the security". The real problem is when it's mostly kids/teens doing this shit.
__________________
Chaturbate Affiliate
dillfly2000 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-19-2017, 09:35 PM   #12
Bladewire
StraightBro
 
Bladewire's Avatar
 
Industry Role:
Join Date: Aug 2003
Location: Monarch Beach, CA USA
Posts: 56,229
Quote:
Originally Posted by dillfly2000 View Post
Yeah people are bastards, sight unseen, they don't think they're doing anything wrong. They usually just use the excuse "I'm testing the security". The real problem is when it's mostly kids/teens doing this shit.
The number of amoral people who are willing to do the wrong thing if they think they wont get caught is astounding.
__________________


Skype: CallTomNow

Bladewire is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
list, ips, honeytrap, 1orglaugh1orglaugh, guys, crack, daily, creating
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.