Menu
iThemes
WordPress Security, Backups & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Plugin Suite
    • WordPress Web Designer’s Toolkit
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

Brute Force Attacks: What They Are & How to Prevent Them

Written by Saylor Bullington on November 4, 2016

Last Updated on April 6, 2022

Brute force attacks refer to a trial and error method used to discover username and password combinations in order to hack into a website. The brute force attack method exploits the simplest form of gaining access to a site: by trying to guess usernames and passwords, over and over again, until they’re successful.

How Brute Force Attacks Work

The brute force attack process is often referred to as exhaustive search. An attacker will systematically check unlimited passwords until the correct one is found.

Software has been developed to aid an attacker in this process. Success depends on the computing power and number of combinations attempted.

Depending on your server settings, an attacker can go through 1000 different password variations in a minute.

Brute Force Attacks

Ways to Prevent Brute Force Attacks

As a user on a website, you are more dependent on the security measures that have been taken by the website owner. One thing you can control is the strength of the password you create.

Website User Tips:

 

  • Make a habit of using a different password for every site you use.
  • Use a combination of lower and uppercase letters, symbols and numbers.
  • Change your passwords often. Change it immediately if a company, you have a registered online account with, informs you they were hacked or compromised.
  • Although it is convenient, avoid “Log in with Facebook” or other social media platforms.
Website Developer Tips:

 

  • Limit the number of login attempts.
  • Use a captcha for logins.
  • Offer a two-factor authentication login option.
WordPress Website Owner Tips:

 

  • Do not use ‘admin’ as your username.
  • Pay attention to the strength meters provided when creating a password and make sure yours is adequate.
  • Install a WordPress security plugin such as iThemes Security
  • Activate WordPress brute force protection.

Are Your Passwords Providing Good Security?

Using strong passwords for all your logins is one of the best online security practices you can develop.

The best practice to follow is creating a different password for every sing website you are registered on. Definitely don’t use the password you use for your bank account on another site.

An average of 30,000 sites are hacked every day.

This should give you an idea of how many people are affected by cyber attacks, and motivate you to use stronger passwords.

Top 7 Passwords of 2016

  1. 123456
  2. password
  3. 12345678
  4. qwerty
  5. 12345
  6. 123456789
  7. football

If you have one of these passwords, you are welcoming brute force attacks. You should change your password ASAP.

Why Passwords Matter

Let’s say you have an account on some website and you’re not too worried if someone gains access to your password because this particular account doesn’t have any useful information.

Imagine that “useless” site get’s hacked and now the attacker has your password to that account.

Even though that specific site may be useless to a hacker, your password isn’t. 

Using the same password on multiple sites is risky.

Let’s say you use that same password on an online shopping site, the hacker now has your password to your account, which has your payment information. Now you have a big problem you have to deal with.

This is why it is important to have different passwords for each website you are registered on.

Use a secure password management tool like LastPass to keep track of passwords.

If you are thinking keeping up with 20 different passwords is ridiculous and you would rather just take your chances, you should check out a secure password management tool like LastPass.

Using a WordPress Security Plugin to Protect Your Website

WordPress website owners should be concerned about brute force attacks. Why?

  • Early versions of WordPress defaulted to the username ‘admin’ and many people either forget or neglect to change it.
  • WordPress does not automatically limit the number of failed login attempts, which can be a big vulnerability for brute force attacks.

Fortunately, there are WordPress security plugins to help with these security issues.The iThemes Security plugin offers WordPress brute force protection in addition to multiple other WordPress security features.

  1. To enable brute force protection, open ‘Settings’ in the iThemes Security menu in your WordPress dashboard.

wordpress brute force attacks2. In Settings, you will find a list of all the different features the plugin offers. Open ‘Local Brute Force Protection.’

Local brute force protection looks only at attempts to access your site. Users are banned per the lockout rules specified locally on your WordPress site.

Here you are able to customize the security details for brute force attacks.

By default, there is a max login attempt of 5 per host and 10 per user. Feel free to increase or decrease these numbers, this is just what we suggest.

You can also increase or decrease the amount of time someone will be locked out of the site after the maximum login attempts.

The ‘Automatically ban ‘admin’ user’ checkbox is not selected by default. I suggest going ahead and doing so after you change your username to something other than ‘admin.’

Doing so will immediately ban a host that attempts to login using the “admin” username.

brute force protection

3. Once you have finished up Local Brute Force Protection settings, save them and move on to Network Brute Force Protection.

Network brute force protection takes it a step further by banning users who have tried to break into other sites from also breaking into yours.

In the most updated version of iThemes Security, an API key is automatically applied for you.

I suggest you also make sure the box to automatically ban IPs that are recognized to be problematic, is checked.

brute force setting

When you save your setting here, an email will be sent to you confirming your API key. You don’t need to do anything else with this, but you can keep the email for your records.

For more tips on WordPress security, check out the free ebook WordPress Security, a Pocket Guide.

Protect Yourself From Brute Force Attacks

Brute force attacks exploit the simplest method of gaining access to a site. You can prevent this with the information provided. Taking time to secure your site is important, and creating strong passwords to reduce the risk of brute force attacks will allow you to rest easy.

Life does happen and you may fall victim to a cyber attack. Do what you can now to protect yourself online.

Protect Your WordPress website with the iThemes Security Plugin

Get iThemes Security Pro
Saylor Bullington
Saylor Bullington

Saylor writes blog posts and designs/develops various projects for iThemes. Saylor loves gardening and is currently at war with all squirrels (if anyone has tips on how to get rid of squirrels, she’s all ears). If she’s not traveling or hanging out in OKC, there’s a good chance she’s in southwest Oklahoma doing manual labor, including roofing, or as her father likes to call it – “building character.”

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
A security-riddled computer monitor. There is a large, orange shield with a slash in the middle of the screen. Surrounding it are a red target, a green skull and crossbones, an orange “bug”, a triangle with an explanation point in the middle and a gray gear.
WordPress Vulnerability Report – March 15, 2023
ip hack
What is an IP Hack?
Patchstack 2022 WordPress Security Review
The State of WordPress Security: Community and Collaboration Help Us All Win
wordpress-vulnerability-report
WordPress Vulnerability Report – March 8, 2023

Respond

Click here to cancel reply.

Get updates on new themes & plugins plus special discounts

About iThemes

  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2023 All rights reserved | Privacy Policy

A Liquid Web Brand © 2022 All Rights Reserved.

Get the Weekly WordPress Vulnerability Report

Vulnerable WordPress plugins and themes are the #1 reason WordPress sites get hacked, but keeping track of every new plugin and theme vulnerability is hard work. Get the weekly WordPress Vulnerability Report delivered right to your inbox to help keep your website secure.

Get the Report
Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap