
Originally Posted by
TechieGuy
I have a plugin that limits the number of login attempts on my blog. The plugin also includes a logging of the IP address and the login ID tried by the IP address. 90% of the time, someone that has tried to log into my blog has tried the user name of "admin" or "Admin", which proves the point of immediately changing the administrative ID for a WordPress blog.
For my blog I also enable two-factor authentication for the admin account, so even if they managed to get the user ID or password, they would need an additional code - that changes every minute - to log into my blog.
ArcadeThunder, did you manage to figure how to get into the dashboard of your blog? Did they guess the user ID and password or go in through another way?