
I have TaB hosted on HostGator and like many other hosting services, they are under attack from the latest botnet:
As I type these words, there is an on-going and highly-distributed, global attack on WordPress installations across virtually every web host in existence. This attack is well organized and again very, very distributed; we have seen over 90,000 IP addresses involved in this attack.
Via HostGator
This botnet is searching for wp-login.php and attempting to gain administrator-level access to WordPress blogs by running through a list of common passwords against the “admin” username.
Here’s what I would recommend: If you still use “admin” as a username on your blog, change it, use a strong password, if you’re on WP.com turn on two-factor authentication, and of course make sure you’re up-to-date on the latest version of WordPress. Do this and you’ll be ahead of 99% of sites out there and probably never have a problem.
Via Matt Mullenweg
That’s really all there is to it. If you are the only one who uses your blog, there is no reason to have multiple user accounts (WordPress Dashboard / Users). And, as Matt Mullenweg says, there is no reason to have a user account named “admin.” There is also little or no benefit in using one of the various WordPress security plugins available. This is a very crude botnet, but even it is sophisticated enough to change IP addresses between login attempts – rendering IP blocking and login limiting schemes useless.
Are you currently experiencing any slowdowns or issues from this latest attack? I have not noticed any problems, so far.