esmi on "Security issues and questions following it"

ساخت وبلاگ

Hello people.

My website is in the middle of brute force attack. We have the latest WordPress and all admin passwords are very strong etc. I have few questions and it would be interesting to receive some answers.
Last night, I've deleted the whole user list, because I need everyone to start new for numerous reasons. Today, that user list is somehow being used.

1) I have a operator from one company doing some work on a plugin, where I emailed him my admin password
2) I used plugin Export User Data from Q Studio in order to export the date to my laptop.
3) My laptop being . Tried Avast and Malwarebytes. Nothing there.
4) Possible export exploit?

I logged in since I have Activity Log plugin and saw in the last 15min a lot of users trying to log in. Went to Miniorgane security login plugin and a lof of them were blocked. The next step is to find something more valuable.
Went to All In One WP Security. Amazing plugin. Is is blocking all of them since somehow the they are using the user list which I have deleted already. Breach happened probably before that? Plugin has the option to block the missing useames and I've activated that with a lot of other feature. U have a 44 blocked IP at the moment. They are blocked for 60min. Will increase to 3h.

I've changed admin useame, password, ftp password, mysql password. Everything has regular backups so no big damage can be done, but still.
Should I take any more steps in order to secure it? Which ones?
Should I permanently ban those IP from accessing the website?

I also have detailed IP addresses with dates and so on. Is there any way to submit them somewhere in order for the check the illegal activity?
I've resolved some of the host and there are tor host for some university in usa or a dreamhack conference.

We have a small student oriented website and this being a high-end attack, I can't seem to think that it's beyond us and somebody is just entertaining themselves.

We also have SSL.

Any thought would be appreciated.

WordPress ...
ما را در سایت WordPress دنبال می کنید

برچسب : نویسنده : استخدام کار wpss بازدید : 268 تاريخ : يکشنبه 3 مرداد 1395 ساعت: 0:16