Site AI Auditαπό την Internet Solutions

Brute-Force Login Attacks: How to Protect Your Website Logins

9 Σεπτεμβρίου 20267 λεπτά ανάγνωσηςΑσφάλεια και SSL
Brute-Force Login Attacks: How to Protect Your Website Logins

Short answer: Brute-force attacks use bots to try huge numbers of passwords against your login pages, and credential stuffing tries username and password pairs leaked from other websites. The protections that actually work are: unique, long passwords for every account; two-factor authentication for anyone with editing or admin rights; rate limiting or temporary lockouts after repeated failures; fewer admin accounts; and blocking or limiting old login endpoints such as XML-RPC where they are not needed. Hiding the login URL reduces noise but is not protection on its own.

If you look at the logs of almost any website with a login page, you will see a steady stream of failed login attempts from addresses around the world. For WordPress sites, the wp-login.php and xmlrpc.php endpoints are favourite targets; shops, CRM portals, webmail and hosting panels get the same treatment. Most of these attempts fail, but it only takes one weak or reused password to hand over the whole site. This guide explains how these attacks work and which defences make a real difference, in order of impact.

How brute-force and credential stuffing work

Classic brute force means trying many passwords for one account – often common usernames such as “admin”, the site name, or author names visible on the site – with lists of popular passwords. Modern attacks are distributed across thousands of compromised machines, so each IP address makes only a few attempts, which defeats naive per-IP blocking.

Credential stuffing uses real e-mail addresses and passwords leaked from breaches of other services. If an editor used the same password for your website and a hacked online shop years ago, attackers may already have the correct pair and will succeed on the first try. Because the attempts look like normal logins, there may be no burst of failures to notice.

Password spraying tries one or two very common passwords against many accounts, staying under lockout thresholds. It targets organisations with many users, such as staff portals.

All three are automated, cheap and relentless. The goal is not your site specifically; it is any site where a guess works.

Defence 1: Unique, strong passwords

The basics stop most attempts. Every account with editing rights should have a long, unique password generated and stored in a password manager. Length matters more than complexity rules: a random passphrase of several words or a generated string of 16 or more characters is far stronger than a short password with forced symbols. Uniqueness is what defeats credential stuffing – a password that exists nowhere else cannot have leaked from somewhere else.

For sites with customer accounts, check new passwords against lists of known breached passwords and reject them, as current guidance from bodies such as NIST recommends, rather than relying only on complexity rules.

Defence 2: Two-factor authentication

Two-factor authentication (2FA) is the single most effective measure against both brute force and credential stuffing. Even with the correct password, an attacker cannot log in without the second factor. Options, from strongest to weakest:

Make 2FA mandatory for administrators and editors. For customer accounts, offer it and encourage it, especially where accounts store payment methods or personal data. Remember accounts outside the CMS as well: hosting panel, domain registrar, DNS, CDN and the e-mail account that receives password resets.

Defence 3: Rate limiting and lockouts

Limiting how many attempts can be made slows automated guessing to a crawl. Common approaches:

Be careful with permanent lockouts: an attacker can deliberately lock out real users by failing logins on their accounts. Temporary, escalating delays are usually a better balance.

Defence 4: Reduce the attack surface

Defence 5: Watch for signs of attack and compromise

Monitoring tells you whether the defences are holding. Useful signals include spikes in failed logins, successful logins from unusual countries or at unusual times, new admin accounts, and password reset requests nobody made. Many security plugins and hosting panels can e-mail alerts for these events. Send notifications to someone who will read them, and review login logs occasionally even when nothing seems wrong. If you see a successful login you cannot explain, treat it as a compromise: reset passwords, revoke sessions and check the site for changes.

Customer logins on shops and portals

Admin accounts get most of the attention, but customer accounts are attacked too – especially on shops that store addresses, order history, loyalty points or saved payment methods. Credential stuffing against customer logins is common because many customers reuse passwords. Measures that fit customer-facing logins without driving people away:

These steps protect customers even when their own password habits are weak, and they reduce support work after incidents.

What helps less than people think

MeasureWhy it helps lessVerdict
Renaming or hiding the login URLCuts bot noise, but does nothing against a known URL or credential stuffing via other endpointsNice extra, not a defence
Blocking countriesAttacks come from compromised machines everywhere; may block real customersSituational
Forced password changes every few monthsLeads to predictable patterns; current guidance advises changing only when compromise is suspectedNot recommended
CAPTCHA aloneAutomated solving services exist; annoys usersUseful after failures, not alone

The OWASP guidance on credential stuffing gives a broader overview of these attacks and countermeasures.

How Site AI Audit helps

Site AI Audit checks the parts of login security that are visible from outside: a valid SSL certificate and HTTPS redirect so passwords never travel unencrypted, security headers such as HSTS and frame protection for login pages, and exposed software versions that make targeting easier. Each finding is explained in plain words with a fix, and paid plans monitor the site so regressions are noticed quickly. Run a free check.

Related reading

The bottom line

Login attacks are constant and automated, but they succeed only against weak, reused or unprotected accounts. Unique passwords stop credential stuffing, two-factor authentication stops almost everything else, and rate limiting, fewer admins and disabled legacy endpoints reduce the pressure further. Put those in place for your website and for the hosting, domain and e-mail accounts behind it, and brute-force attempts become harmless noise in your logs.

FAQ

Is my site under attack if I see many failed logins?

Almost certainly it is being scanned, like nearly every site with a login page. It becomes a real problem only if an attempt succeeds, which is why unique passwords and two-factor authentication matter more than the volume of failures.

Does changing the WordPress login URL stop brute-force attacks?

It reduces automated noise against the default URL, but attackers can still use other endpoints and leaked credentials. Treat it as a small extra on top of strong passwords, two-factor authentication and rate limiting.

Should I disable XML-RPC in WordPress?

If you do not use the mobile app, remote publishing or services that depend on it, blocking XML-RPC removes a popular brute-force endpoint. Check your integrations first, since some plugins and services still use it.

Which two-factor method should I choose?

Passkeys or hardware keys give the strongest, phishing-resistant protection, and authenticator apps are a good, widely supported choice. SMS and e-mail codes are weaker but still far better than a password alone.

Can a strong password alone protect my admin account?

A long, unique password defeats guessing and credential stuffing, but it can still be phished or stolen by malware. Two-factor authentication covers those cases, so use both for any account with admin rights.

#Hacked website#Website security#WordPress security
Ελέγξτε τον δικό σας ιστότοπο — δωρεάν.Τι να διορθώσετε στον ιστότοπό σας — και από πού να ξεκινήσετε.
Ξεκινήστε δωρεάν

Περισσότερα από το blog

Όλα τα άρθρα →
Internet Solutions

Περισσότερα από την ομάδα μας

Από την Internet Solutions. Δοκιμάστε και τα άλλα προϊόντα μας — το καθένα σας εξοικονομεί χρόνο με διαφορετικό τρόπο.

internet-solutions.net ↗
01Αυτόματες αναρτήσεις στα social
PostRSS

Οι νέες αναρτήσεις από τη ροή RSS σας πηγαίνουν αυτόματα σε Facebook, X, LinkedIn, Telegram και σε 60+ ακόμη δίκτυα.

Δωρεάν πλάνο · από το 2014Επίσκεψη →
02Ζωντανή συνομιλία AI για ιστοσελίδες
Talkmio

Η ιστοσελίδα σας απαντά στους επισκέπτες 24/7 από το δικό σας περιεχόμενο, στη γλώσσα τους.

Δωρεάν πλάνο · χωρίς κάρταΕπίσκεψη →
03AI βοηθός
Ask Mio

Συνομιλία, κώδικας, σχεδιασμός, γραφή και έρευνα. Το Mio επιλέγει το καλύτερο μοντέλο για κάθε εργασία.

Δωρεάν πλάνοΕπίσκεψη →
04AI αυτόματος πιλότος για blog και social
AI Blog Autopilot

Η AI γράφει άρθρα SEO 2.000–3.000 λέξεων και κοινοποιεί το καθένα σε 58+ κοινωνικά δίκτυα.

Τα 3 πρώτα άρθρα δωρεάνΕπίσκεψη →
05Σε βάθος SEO crawl
Site SEO AI Audit

Πλήρες SEO crawl σε 7 τομείς, μαζί με την ορατότητα στην αναζήτηση AI, με διορθώσεις ταξινομημένες κατά αντίκτυπο.

Ο πρώτος έλεγχος δωρεάνΕπίσκεψη →
06Ροές RSS και προϊόντων
RSS Feed Creator

Δημιουργήστε RSS από οποιαδήποτε ιστοσελίδα, καθώς και ροές προϊόντων για Google και Meta που ενημερώνονται μόνες τους.

Δωρεάν πλάνοΕπίσκεψη →
07Ανάπτυξη ιστοσελίδων και SEO
Internet Solutions

Ιστοσελίδες, e-shops και εξειδικευμένα συστήματα — τα σχεδιάζει, τα αναπτύσσει και τα υποστηρίζει η ομάδα μας.

Από το 2011Επίσκεψη →
Site AI Audit
Επισκόπηση απορρήτου

Αυτός ο ιστότοπος χρησιμοποιεί cookies ώστε να σας προσφέρουμε την καλύτερη δυνατή εμπειρία. Οι πληροφορίες των cookies αποθηκεύονται στον browser σας και εξυπηρετούν λειτουργίες όπως την αναγνώρισή σας όταν επιστρέφετε και τη βοήθεια προς την ομάδα μας να καταλάβει ποιες ενότητες του ιστοτόπου βρίσκετε πιο ενδιαφέρουσες και χρήσιμες.