There have been several other posts about this issue with BH in the past few days. You or your client DO need to contact BlueHost.
My client called Bluehost, and I am able to access the website again. Everything seems normal again so far, but I am only “white listed” for the next 72 hours. They want me to run a malware and virus scan before I can be permanently white listed again. This is so strange.
No, it’s because of massive brute force attacks on servers hosting WP sites – huge problem in the past week or so — see:
http://ww.wp.xz.cn/support/topic/brute-force-attacks-and-wordpress?replies=2
@wpyogi – where is the link to the thread about this issue? I like to read it.
Google will find you MANY more articles on the topic too…
@wpyogi – Thank you for that bit of information.
I just ran Trend Micro and it found several troj_gen viruses. I don’t know how I got so many or how I got them. I just hope it wasn’t a result of the plugin.
Plugin Author
Austin
(@austyfrosty)
It’s not from my plugin. If you have a simple password or an “admin” username you could have been hacked. This plugin doesn’t modify login access, just the design.
Plugin Author
Austin
(@austyfrosty)
I’ve got an brute force protection extensions for Custom Login which can be found on Extendd.com.
Hi Austin,
Bluehost does not think my website was hacked. Here’s what we think happened as a result of using the plugin.
As a result of applying the new settings for this plugin, I explained to Bluehost support that I was adjusting the settings of a login page styling plugin, and in order to see the results, I had to constantly look at the login page. When there are an excessive amount of hits on a login page from the same IP address, Bluehost will automatically blacklist that IP address.
I was hitting the login page so many times, that their automated system at Bluehost thought I was a stranger trying to hack into the website. They explained that there’s a lot of that kind of thing going on and by blacklisting an ip address is one way they were trying to protect the website (which I actually think is good).
They asked me to scan my computer for malware and viruses for hours and everything’s ok.
I didn’t think your plugin had malware or viruses that I uploaded, but I thought I would ask anyway because so many people have been infected that maybe they might not have been aware of it.
Bluehost said to give it about 72 hours to make sure I’m white listed again and to call them back if I’m not.
Thanks for all your help,
Laura
Plugin Author
Austin
(@austyfrosty)
Gotcha!
Yeah, now is not a good time to load your own wp-login page a few hundred times with all these brute attacks. 🙂