How to catch bots and robots with a list of prohibited logins
Cerber uses the list of prohibited usernames to reinforce protection by catching bots and hackers
As you already know, there is a small, but useful feature that called a list of prohibited logins/usernames. This is a comma-separated list of usernames you do not want to be used on your website in any circumstances. That’s it? Nope, there is no “just in case” features in the WP Cerber Security plugin. But how does Cerber use logins from the list to reinforce protection? First of all, the plugin does the following.
- Login or registration with a prohibited username or a username that match REGEX pattern is not permitted.
- Attempt to log in with a prohibited username will be denied and an IP address will be blocked.
Most importantly, using the list of prohibited logins and the Custom login URL together helps the plugin being smart and detecting and catch bots/robots/hackers easily.
If your list is still empty, you definitely have to put on that list the following (commonly used by bots and hackers) usernames: admin, administrator, manager, editor, user, demo, test.
Since v. 5.8.6 you can use regular expressions (REGEX) in the list of prohibited usernames. Specify as many patterns as you need. To specify a REGEX pattern wrap a pattern in two forward slashes like /admin.*/. All comparisons are case-insensitive.
Read more how to create another trap with a Custom login URL.
Last posts from WordPress security blog
- WP Cerber Security 8.1 March 6, 2019
- How to protect WordPress effectively: a must-do list March 1, 2019
- WP Cerber Security 8.0 February 20, 2019
- Development version 7.9.9 February 10, 2019
- Manage multiple WP Cerber instances from one dashboard February 4, 2019