Is it smart to scan apache logs for wp_login.php -- Brute Force blocking?

jim.thornton

Verified User
Joined
Jan 1, 2008
Messages
334
I was just looking at hiding the Brute-Force notifications and I came across this post: https://www.directadmin.com/features.php?id=1695

It is talking about setting up DA to scan for failed wp_login.php attempts. However, it doesn't know the difference between a successful login or a failed login. So, is it smart to have this enabled? If it is enabled, how long of a time period does it scan? For example, I have my Brute Force attempts to 25 I think. So, will it block an ip address after 25 attempts in 1 day, 7 days, all time?
 
Back
Top