VacantServer WordPress sites are getting hammered with bad logins and probes. We’ve implemented a plugin to log failed login attempts to syslog, and a Fail2Ban filter for the same. If you run these on RedHat, you’ll need some additional configuration info… here it is: WordPress login failure regex (error_log):
|
1 |
^%(__prefix_line)sAuthentication failure for .* from <HOST>$ |
Apache nohome regex (error_log):
|
1 |
[[]client <HOST>[]] File does not exist: .*/~.* |
[...]





