Did you ever feel like your website or blog login page is ridiculously fragile and reachable, and could be easily broken in by an intruder?
Did you ever feel like your website or blog login page is ridiculously fragile and reachable, and could be easily broken in by an intruder?
Personally I hate to think of hundreds of people playing with my door lock hundreds of times a day. It’s the same with my blog login page.
On WordPress, there are two main potential vectors of bruteforce intrusion:
* http://my-site.com/wp-login.php, which is the login page
* http://my-site.com/xmlrpc.php, which is an API gateway for interacting with third party applications.
This plugin adds one security layer in front of your login page, and by the way you can also disable XML-RPC with a simple checkbox if you don’t need it (XML-RPC is a WIDELY used vector of attacks).
The idea is simple: you choose a pair of words, and when you want to access your login page, you just have to provide them in the URL like this: http://my-site.com/wp-login.php?word1=word2. That’s all!
If you try to access your login page without this pair of words, you get a configurable error message, where you can insult the attacker as much as you want 😉
/wp-content/plugins/wp-login-door
directory, or install the plugin through the WordPress plugins screen directly./wp-content/plugins/wp-login-door
directory, or install the plugin through the WordPress plugins screen directly.You can disable the plugin from your FTP server.
Then login as usual, reactivate the plugin, and check your word pair.
I don’t know if the beerware license is GPL 2 compatible, but if you like this plugin and if we meet someday, you can buy me a beer.
Yes!