Lately we have been seeing a lot of attacks against WordPress and Joomla! installations with weak admin passwords. The attack is carried out by a script attempting to log in to the admin panel using a list of weak passwords. The use of a strong admin password is essential to the security of your website. Always follow the strictest password rules when creating passwords for your website content management system (CMS).
In addition to a strong password, it is a good idea to use a CAPTCHA to protect your login page. A CAPTCHA is designed to allow humans but stop computers from submitting a web form. In this case, you want to stop dictionary attacks on your admin login, which are performed by a script trying to log in using a predefined list of weak passwords. A CAPTCHA will thwart the majority of these automated password attacks because the hostile code will in most cases be unable to solve the CAPTCHA.
Some plugins we have tried for WordPress:
For Joomla! you could use something like:
EDIT: Thu Apr 11 09:54:19 PDT 2013
There has been a huge spike in password attacks against WordPress admin panel logins over the past 24-48 hours. Protect your admin panel with a strong password and a CAPTCHA!
Sign up for Free Email Updates
Enter your name and email below to sign up for free daily email updates.
[inbound_forms id=”2447″ name=”Contact Form”]