Results 1 to 8 of 8

Thread: [How To] Restrict access to WordPress admin areas (wp-login.php)

Threaded View

Previous Post Previous Post   Next Post Next Post
  1. #3
    Matt's Avatar
    Matt is offline GlowHost Administrator
    Join Date
    Jan 2005
    Location
    Behind your monitor
    Posts
    6,430

    Default

    Quote Originally Posted by GDufresne View Post
    My question is this:
    Is this restricted IP access to wp-login.php going to be the new standard with GlowHost? . . . or is it simply a temporary response to the latest round of brute force attacks?

    I absolutely appreciate GlowHost's vigilance when it come to protecting our sites, but permanently restricting access to wp-login.php is not something I'd like.
    Hello GDufresne, welcome to our forums.

    We are not sure at this time if this is going to be the standard, but it may certainly become the standard if WordPress or Softaculous (or both) do not devise a solution to the problem with this software. It would be better if their software allowed the user to specify a different file or location for the admin area other than wp-login.php since this is the file the robots have been programmed to attack.

    Here is one such plugin that can possibly help:
    http://wordpress.org/plugins/rename-wp-login/

    It would also be good if their software allows the person installing it to password protect their wp-admin folder using Apache's htpasswd feature. htpasswd is simply what cPanel calls Password Protected Directories and all it does is enable this functionality in .htaccess to password protect certain areas of your site as you see fit.

    This method may actually be better because when these robots fail to login a set number of times, they will be automatically added to the server's blacklists in the firewall. This means if all users are using this method, there are lots of sites contributing to build the firewall rules against known bad robots.

    The reason this is not the default cure for the problem at this time, is because we don't have a way of doing this each time someone decides to install WordPress on their account using Softaculous auto-installer in cPanel, or if they do it by hand.
    Last edited by Matt; 01-19-2014 at 05:22 AM.
    Send your friends and site visitors to GlowHost and get $125 plus bonus!
    GlowHost Affiliate Program | Read our Blog | Follow us on X |

Similar Threads

  1. Referencing a PHP Class inside a PHP Include
    By rickpugh in forum Programming Talk
    Replies: 1
    Last Post: 01-22-2006, 08:30 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

1 2 3 4 5 6 7 8 9 10 11 12 13 14