Skip to content
This repository has been archived by the owner on Jan 20, 2021. It is now read-only.

Found a way that hackers are able to figure out the "hidden" login folder url! :( #42

Open
eturner69 opened this issue Dec 1, 2017 · 4 comments

Comments

@eturner69
Copy link

If you are allowing people to register on your site (for instance you are using woocommerce to sell things) then all someone has to do is use this and it then shows the 'hidden' folder name in the URL!
http://yoursite.com/wp-register.php

I noticed some hacking activity which wordfence blocked as someone was hammering at the 'hidden' login. After looking at their activity history it was quite obvious this is how they figured it out.

Not sure how to go about getting this fixed?

@Presskopp
Copy link

see also #27

@maximejobin
Copy link
Collaborator

This could be enhanced to make the URL harder to find.

@elgaspar
Copy link

elgaspar commented Apr 10, 2020

http://example.com/wp-register.php page of WordPress is auto redirecting to http://example.com/login . By changing slug from 'login' to something else, it doesn't redirect to the login page.
Obviously, this is not a proper fix, but it can work for some people that don't necessarily need the 'login' slug for the login page..

#35

@stanwmusic
Copy link

I can confirm, http://oneofmywebsites/wp-register.php just took me to the login page and I logged in and I have registration disabled on that site and "login" renamed to a different name.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

5 participants