dwinden on "[Plugin: iThemes Security (formerly Better WP Security)] Unlock your backend (hack)"

ساخت وبلاگ

dvascheta
Member
Posted 30 minutes ago #

Hello!

I've just invented a hack. May be it is not new, but also may help one.

So if you tued on admin area slug and can't access login screen, you should find and duplicate wp-login.php to smth, for example wp-login2.php and just open yoursite.com/wp-login2.php

This worked for me. Plugin doesn't block or redirect from renamed file.

https://wordpress.org/plugins/better-wp-security/

dwinden
Member
Posted 3 minutes ago #

@dvascheta

Thank you for sharing that workaround.

However renaming or copying to wp-login2.php is not a very good idea.
It may help you getting back into the Dashboard but it may also help attackers find access to your Dashboard login page.
Attackers are constantly scanning for copies of files and wp-login2.php is probably one of the first ones they will try.

If you do this do it temporarily and rename or copy to a random file name like 1j5hgd96to2.php

I prefer to temporarily rename the better-wp-security folder which will auto deactivate the plugin. A much safer approach.

Well actually I prefer to solve the root cause of the problem ;-)

dwinden

WordPress ...
ما را در سایت WordPress دنبال می کنید

برچسب : نویسنده : استخدام کار wpss بازدید : 220 تاريخ : پنجشنبه 10 تير 1395 ساعت: 5:00