I attempted to login to my Wordpress administrator panel today, but there was a new login screen that I've never seen before, see screenshot below.
The specific message you will see is "The server http://yourwebsite:80 requires a username and password. The server says: WordPress attack protection CAPTCHA. Enter username: xxxx Password: The result of math xxxxx.
The login now requires you to input a predefined username of xxxx and an addition password of xxxx. What I thought was really weird was, I tried to login to another one of my Wordpress sites, and it prompted me with the same login screen, and showed the same username and password. Is this a legitimate Wordpress CAPTCHA, or is it the hackers trying to get access to our site? I really do not know. I'm writing this post because I didn't see anything else on the web talking about this yet, so I'm hoping someone else has seen this as well that's knowledgeable and can shed some light. I'm afraid if I enter the credentials, maybe my site will be compromised. Therefore I did not yet login.
Update 9AM
Spoke with my web host, and they said that they employed this security feature to block the botnets from accessing my website.
2 comments:
Legitimate. See http://www.webhostingtalk.com/showpost.php?p=8642804&postcount=249
This same problem began this morning for me as well (April 21, 2013) on all my Wordpress sites. I am scouring the internet for a solution and have found none. This post is the first I have found that even addresses the issue. This is the exact message I am getting: 'A username and password are being requested by http://bwovfd.com. The site says: "WordPress attack protection CAPTCHA. Enter username: wstpmk Password: The result of math 23+3"' Of course I am not able to log in because there is no field to type the CAPTCHA answer.
Post a Comment