Brute force is one of the most common methods attackers use to get into a server. It is used against many targets:
- SSH
- FTP
- Email accounts
- CMS logins such as WordPress and Joomla
Recently there has been a big increase in brute force attacks against WordPress and Joomla sites. They come from large networks of infected servers, so an attacker can test thousands of passwords per minute against one site.
During an attack, the server load, memory use and CPU use all rise. On servers with limited memory the system can start swapping and fail, and the web server may hang until the server is restarted. Once attackers get into a WordPress or Joomla admin area, it is easy for them to upload malware, phishing pages or spam mailers.
How the protection works #
Every time a login fails, the server records the IP address. If repeated failed logins come from the same IP, that IP is blocked from all login forms on the server, and the attacker only sees an “Access denied” message.
The result: later login attempts from that IP never reach WordPress, which protects the server’s load, memory and CPU. The server stays stable during brute force attacks.
Blocked by mistake? #
Sometimes it is not an attack: a real user forgets their password and triggers the protection. In this case, instead of “Access denied”, you will see a CAPTCHA test. Solve it and your IP address is unblocked and the login form appears again.
To stay safe, use long, unique passwords and enable two-factor authentication where possible. See also how to protect your website from hacking.
Related service: Hyyat Host WordPress hosting includes brute force protection, free SSL and 24/7 support.
