5 Steps to stop wordpress brute force attack
When I trying to login our company blog site for news update, I get a message showing "WordPress Login Temporarily Disabled" and a support page link for problem fixing. After doing my research, it's because of "brute force attack" for wordpress site, our company blog is one of the victims and our hosting company blocked the login access for any user. After a bit research, we collected following solutions to deal with wordpress brute force attack.
Brief introduction of brute force attack
Brute force attack is the most basic hacking method to gain access to a site: it tries usernames and passwords over and over again until it gets in. Those victim sites using simple user name and password can be compromised easily by this hacking. At the meanwhile, because of the over and over again trying, the server memory/cpu usage goes up dramatically, if there's mass trying on lots of sites, the hosting server can be brought down quickly.
5 efficient steps to stop brute force attack
step1. Use strong username and password
Basic but crucial configuration to maintain a safe site. For wordpress, it's highly recommended to change the default user "admin" to something else you prefered. It can be done through phpmyadmin panel -> open your database -> click on "wp-users" -> click edit button beside the user name -> rename the "admin" to your prefered word -> click save at the buttom to make the change. We can also set a strong user password there directly.
It's crucial step after we have wordpress installed. No matter how the hacker is trying, they can not get in our site even the server is brought down. Our data is still safe.
step2. Hide the login page
It doesn't mean to remove the login link on website home page, it means to change the login URL to something else other than wp-login.php or wp-admin. We highly suggest to have plugin "stealth login page" or "HC Custom WP-Admin URL" installed. We can fully custom the login url as we liked thus hackers can not get it in any way.
step3. Install wordpress security plugins
We have provided a list of 6 leading wordpress security plugins. It's highly recommended to have them installed for high level protection. Free and easy to do, so why not use?
step4. Use CDN service
CDN is great to filter those spam traffic and reduce the hosting server loads. It's not only good for single site health but for entire hosting server. We highly suggest start with free CDN provider "Cloudflare", it's good enough for small to medium size. Pretty easy to configure.
step5. Use a decent hosting provider
A good provider not only prepares good hosting servers but good policies to keep our site alive. Normally, when there's such attack on customer site, many hosters will shut down customer site directly to save their server. But a good hoster like inmotion will try to fixe the problem on server end. For instance, our site is being attacked but they only blocked login access with fix solutions. This is what called customer caring.
Further resources of brute force attack:

Asia is well known for its prosperous economy and population. However, there're not so many famous data centers to support the fast growing IT requirements. People always need to research a bit in order to find the right
Security – Since we don't have access to any equipment, we can't get a single piece of security configuration to trust with. Just think about the amount of users and what the result would be in case the server compromised. For example, the yahoo mail system got multiple hacking before and millions of email id/password were published online.
Being the biggest domain registrar on the planet, godaddy is selling domain names by per second frequency. While people purchase a domain name from godaddy, the great price notice in configuring website hosting is almost irresistible to most people. From their official reports, there're over 10 millions US clients and multi millions international clients being hosted on their servers. Not to mention their huge domain database, their hosting users statistics is almost horrible comparing to most competitors.
No matter how people talk about this name, we have to accept the truth. Endurance does not offer any hosting package directly but selling on hundreds of popular brands like ipage, fatcow and justhost. Their rank of biggest linux provider greatly relies on acquisition over hostgator and bluehost. These two brands had served multi millions clients on the globe and well recognized by most people. Actually, their linux hosting plans are considered industry standards and followed by many companies. When we liked a linux hosting plan, check first if it's offered by endurance brand because they're everywhere nowadays.
Being the windows server provider, microsoft also provides hosting itself. From netcraft report, microsoft is ranked the biggest windows hosting provider. Especially for windows cloud, microsoft manages total of 23400 servers(22300 servers for amazon). Microsoft currently is most well known for it's cloud service "
You might be surprised about this but this company does offer the most vps servers. From editorial anylisis, it's because of their huge shared hosting users. Only $0.99/yr to try out and then you pay $5.99/mo. However, once your website grows up mostly you will need VPS support, thus it's reasonable for clients to keep the service for easier management. I can't say 1and1 is doing good for web hosting service, however they indeed support large amount clients.
The most well known and reputable dedicated server provider. The rackspace server is not cheap but you get for the pay. Rackspace servers are mainly targeted for enterprise business with advanced configuration. The company has a team of professionals from the industry and they're actually building the standards. They company is doing close co-operation with popular communities like NASA, their produce "OpenStack" is widely used by many cloud providers.
The most reputable and biggest cloud service provider. Amazon is also the very first company for business cloud service offering. Since 2006, amazon has started their cloud service and has been powering dozens of world leading names including Dropbox, Adobe, Twitter, NASDAQ and NASA etc. Not only for enterprise support, amazon cloud is also open for personal service, for example its free 5GB cloud drive service.