Viewing 2 replies - 1 through 2 (of 2 total)
  • Blocking IP addresses isn’t the best solution really. There are a couple of security plugins you can get though which are great at stopping brute force attempts. I’ll let you choose the one that’s right for you but the higher rated, more popular ones are the best (of course).

    The best thing to do in the scenario is to block after X failed attempts. Even perhaps try hiding wp-admin and other sensitive areas as well.

    The main problem with IP blocking is you could prevent genuine people going on the site. Hope that helps anyway.

    🙂

    There are a number of ways to impede brute force attacks. IMHO best to use several for a layered defense. One approach that I like to include is CloudFlare page rules – blocks the bad bots at the DNS layer, before they hit my server or site. Downside – uses up two of my three page rules on the free plan.

    For both *mysite.ext/wp-login* and *mysite.ext/wp-admin*
    Browser Integrity Check: On
    Security Level: I’m Under Attack
    Cache Level: Bypass

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘Stopping brute force attacks’ is closed to new replies.