This is a repost from another forum, from a representative of BeyondHosting.
"As of this week a huge new botnet consisting of over 100,000 compromised servers has began attacking wordpress installs by trying to brute force the login page.
Here are a few key things to prevent you from getting compromised and taken offline.
1. Modify your login username to something secure, not admin1 or weak user. Use a random set of chars if you can or set it to a username that is not easily guessed.
2. Set a secure password on the new user. Utilize password websites such as Strong Password Generator We recommend utilizing a password encryption service such as https://lastpass.com/
3. Make sure you've removed the admin user from your wordpress.
4. Insure wordpress is up to date and all plugins and THEMES are as well.
5. Secure wordpress with .htaccess to block all unknown ips.
.htaccess example.
Code:
<Files wp-login.php> Order Deny,Allow Deny from allAllow from replace-with-your-ip </Files>
If your server becomes heavily loaded with php processes its most likely due to this attack. We are currently receiving almost 1Gbit of traffic solely directed to wordpress sites and submitting password data."
I, like a lot of you, have several WP sites. Protect your site before it is too late! This was posted just a few minutes ago.
"As of this week a huge new botnet consisting of over 100,000 compromised servers has began attacking wordpress installs by trying to brute force the login page.
Here are a few key things to prevent you from getting compromised and taken offline.
1. Modify your login username to something secure, not admin1 or weak user. Use a random set of chars if you can or set it to a username that is not easily guessed.
2. Set a secure password on the new user. Utilize password websites such as Strong Password Generator We recommend utilizing a password encryption service such as https://lastpass.com/
3. Make sure you've removed the admin user from your wordpress.
4. Insure wordpress is up to date and all plugins and THEMES are as well.
5. Secure wordpress with .htaccess to block all unknown ips.
.htaccess example.
Code:
<Files wp-login.php> Order Deny,Allow Deny from allAllow from replace-with-your-ip </Files>
If your server becomes heavily loaded with php processes its most likely due to this attack. We are currently receiving almost 1Gbit of traffic solely directed to wordpress sites and submitting password data."
I, like a lot of you, have several WP sites. Protect your site before it is too late! This was posted just a few minutes ago.
Dislike ads? Become a Fastlane member:
Subscribe today and surround yourself with winners and millionaire mentors, not those broke friends who only want to drink beer and play video games. :-)
Access Restricted: Unlock 1,000,000+ Posts
Stop Peeking Through the Keyhole.
Open the Door.
You hit a wall because the best advice isn't free—it's earned. Since 2007, MJ DeMarco has been active here daily (99.9% active rate), building a war room for entrepreneurs who refuse to settle for mediocrity.
- Active Daily: Life-changing content posted dozens of times every day. No dead threads.
- MJ's Inner Circle: Direct access to the author of The Millionaire Fastlane.
- Vetted Network: Connect with founders scaling to 7 and 8 figures.
- Proven Roadmaps: Strategy over motivation. Execution over "hustle porn."
"SCALED TO 6-FIGURE MONTHS"
"Tips and advice here saved me from huge mistakes, others allowed me to scale my business to 6-figure months."— User MitchC
"INSANE QUALITY OF PEOPLE"
"The number of high quality people I've met from this forum has been insane. All of it predicated on building real value."— User Richard Peck
"You are the average of the five people you surround yourself with."
Are you surrounding yourself with success?

