The last four months I have been noticing a large amount of bots trying to brute force wordpress on domains that do not run wordpress.
They use a very unknown Perl web framework that has a login of its own
(with absolutely no brute force protection in any way unless you count captcha), but since the brute force was just for wordpress the Perl system's are left unscathed.
The first course of action was to ban it from the sites, that was easy. But after a few months of reviewing the logs and finding this IP constantly trying the same thing. Well, that made me a little mad so I started redirecting this IP to a 34 terabyte file. That slowed it's requests to about 8 per day instead of 50 a day.
When I searched the IP and find out more information. There was a few reports on the reason why they try to brute force wordpress is to hold the website for ransom.
I don't expect any of your answers to be like mine. How to slow brute force with spam. But by redirecting the IP to another server with a huge file did increase the servers resources that where being attacked.
Ideally i would like a solution that could slow the brute force requests and reduce the load the attacks have on the servers.
Could
sleep(9000000); work better?
Could captcha in the login form be reliable enough to stop brute force ?
Posts are HTML formatted. Put <p> </p> tags around your paragraphs. Put <code> </code> tags around your code and data!
Titles consisting of a single word are discouraged, and in most cases are disallowed outright.
Read Where should I post X? if you're not absolutely sure you're posting in the right place.
Please read these before you post! —
Posts may use any of the Perl Monks Approved HTML tags:
- a, abbr, b, big, blockquote, br, caption, center, col, colgroup, dd, del, details, div, dl, dt, em, font, h1, h2, h3, h4, h5, h6, hr, i, ins, li, ol, p, pre, readmore, small, span, spoiler, strike, strong, sub, summary, sup, table, tbody, td, tfoot, th, thead, tr, tt, u, ul, wbr
You may need to use entities for some characters, as follows. (Exception: Within code tags, you can put the characters literally.)
| |
For: |
|
Use: |
| & | | & |
| < | | < |
| > | | > |
| [ | | [ |
| ] | | ] |
Link using PerlMonks shortcuts! What shortcuts can I use for linking?
See Writeup Formatting Tips and other pages linked from there for more info.