Blocking WordPress brute-force attacks automatically at the hosting edge
Summary
Manuel Schmitt announces a free hosting firewall that automatically detects and blocks brute-force attacks on WordPress logins. The firewall was introduced on 1 July 2020. The feature was free of charge and active without manual activation.
Ideas
- Central detection can protect many WordPress installations without individual plugins.
- Automatic activation also reaches customers who do not configure security features themselves.
- Heavily changed login paths can bypass path-based detection.
Insights
- Platform protection works broadly but must make its assumptions about application paths transparent.
- Brute-force protection complements updates and strong accounts, but does not replace them.
Facts
- Unusually renamed WordPress paths could fall outside the detection.
Recommendations
- Combine rate limits with MFA and prompt WordPress updates.
- Monitor false positives and attacks on alternative authentication endpoints.
References
Read the original article on Hostblogger
Links to the original source and the Web Archive open in a new tab.