boyfalldown
Suspended / Banned
- Messages
- 17,486
- Name
- Hugh
- Edit My Images
- No
I've always used the limit login attempts plugin for wordpress. It logs access attempts with user names as well. Most of the time the user attempted is 'admin' which doesn't worry me as I changed this when set ing WP. I've noticed a few times lately that the correct user name has been attempted instead. Any ideas how they find this. I hide wp-config one level up from my home page so its outside of my public HTML folder and has permissions of 600 anyway so I don't see they could have accessed the database through this. Any suggestions?