• Design
  • SEO
  • Portfolio
  • Why Choose Us
  • Blog
  • Contact
  • Facebook
  • Google+
Precise Online ManagementPrecise Online Management
  • Design
  • SEO
  • Portfolio
  • Why Choose Us
  • Blog
  • Contact
  • Facebook
  • Google+

Locking Down Your Login Page

Renaming Your Login Page

Locking Down Your Login Page

October 30, 2017 Security

Approximately 28% of websites on the internet are using the WordPress platform. From small / mid-sized businesses to schools, hospitals, and even police departments, the range of WordPress sites has never been larger. I can’t help but guess when I first load a new site if it does, in fact, run on the platform. There are visual cues on the front end and indicators in the source code that make it fairly easy to determine if that is true. Rather than scrutinize every section of a website, I first tend to add /wp-login.php to the end of the domain and see if the login page is present. I expect to get some results from smaller businesses and companies but am always surprised when I see government and larger businesses show the login page instead of a 404 error page.

It’s not that I don’t think that developers aren’t using strong usernames and passwords. WordPress does a great job of generating a random string of characters for passwords that would take supercomputers ages to guess the correct combination. More often than not, too many failed login attempts will result in that users’ ip address being banned preventing them from further attempts.

So, what is the problem? The problem is that there are a lot of these so-called hackers and spammers. Most of them from overseas. They are the pests of the internet and are relentless in their attacks. While it is unlikely they will gain access by doing a brute force attack, the possibility of exploits will always exist. All it takes is a vulnerable plugin or theme to allow an intruder to potentially collect information that can help attack a site. Knowing where the login page is makes it too easy should an exploit work successfully. Even if it doesn’t, multiple attempts from multiple users cause stress and performance issues on the server which could make legitimate visitors suffer.

Moving the login page

You’ve heard the saying, “the best defense is a good offense”. In this case, don’t give an attacker the advantage of knowing where your login page is. You have the option of renaming it from wp-login.php to whatever you’d like. Unfortunately, WordPress does not directly offer the option to rename the page but there are several methods you could apply to do so. Writing rules in your .htaccess file is one way. But it can be confusing to developers and designers who aren’t familiar or comfortable with this file. There are also plugins that you can install that simplify the process. However, you want to make sure this plugin is widely accepted and updated on a somewhat frequent basis. There is one such plugin which is widely used for security and has an option to rename the login page.

All in One WP Security & Firewall
Active Installations: 600,000+ | Last Updated: 2 Months Ago | As of 10/30/17
All in One WP Security & Firewall offers a variety of security features to help secure your WordPress website. In a future post, I’ll have a comprehensive review of the plugin. But for now, we’ll remain on topic with the rename login page feature. It is as simple as installing the plugin and entering the new login page name and hitting the save button.

Setting up the plugin

Step by Step instructions

  1. Navigate to Plugins / Add New in your wordpress dashboard
  2. In the Search plugins… box enter “All in One WP Security & Firewall”
  3. Install and activate the plugin
  4. Scroll down to WP Security in the sidebar and choose Brute Force in the sub menu
  5. This will take you to the Rename Login Page tab where you can select the checkbox to enable the feature
  6. Enter whatever page name you would like in the blank box and hit the Save Settings button and you’re done!

Rename Login Page

The next time you want to log in you will use that url to access the backend of your website. There is a warning message on the page which I advise to read if you’re worried about messing something up. However, we’ve used this feature across many websites and hosting environments and never had an issue. If for some reason there is a problem simply rename the plugin folder all-in-one-wp-security-and-firewall in your sites’ “plugins” directory to something else through FTP or File Manager. This will restore the default wp-login.php page.

Still not convinced?

Below is a screenshot of attackers trying to gain access to just a few domains that have their default login page unaltered. I have also blurred the domains and file paths for obvious security reasons. You can see by the frequency and number of different ip addresses just how determined these people are.

WP Login Page Attacks

Now imagine you are responsible for maintaining dozens or even hundreds of WordPress sites. Unless you are looking at the log files you would have no idea just how aggressive these attacks can be. I really hope that awareness of this problem increases in the community. It is an easy fix that anyone can apply. Of course, at Precise Online Management, our policy has to always been to rename our customers’ login page. No matter if they are hosted by us or not.

0 0 votes
Article Rating
Tags: LoginSecuritywordpress
Share
0

About Ryan Faucher

Owner-operator of Precise Online Management. I also manage Kettlebell Krusher, a website dedicated to all things kettlebell as well a blog for my weight loss progress.

Subscribe
Notify of
guest
guest
1 Comment
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
trackback
My Favorite Security Plugin - All In One WP Security & Firewall
June 29, 2018 8:32 am

[…] briefly went over one of my favorite features of the plugin in another post titled Locking Down Your Login Page. The purpose of this feature is to obscure your login page and rename it to something other than […]

0
Reply
wpdiscuz   wpDiscuz

Categories

  • News
  • Niche Dreams
  • Reviews
  • Security
  • SEO
  • Tips

Recent Posts

  • 9 Benefits of Social Media for Your Organization
  • Advantages of Having Marketing Research Samples
  • Link Building Services: How To Find A Trustworthy Provider
  • SAS Affiliate Review and Tips for Affiliate Marketers
  • Comparison Of The Best Link Indexing Service Features & Benefits

Archives

  • January 2022
  • January 2021
  • October 2020
  • September 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
Ready to get started? Pick and choose your website and / or SEO services Order Services

© 2025 · Precise Online Management, LLC.
This site is owned and operated by Ryan Faucher

  • Visit Us on Facebook
  • Visit Us On Google+
Prev Next
wpDiscuz
X
WEB DESIGN SPECIAL PRICING - Over 60% off design packages through Fiverr
See Details