Hello, this is Rob coven here. Now your admin username is extremely important. But everything I say in this video would apply to any username you use on your WordPress site. Indeed, what I am about to tell you, you can apply to any username you use on the internet today. This set of videos is not just about WordPress, security, uncovering elements of all your online security. And online security is going to be huge in the years and decades to come.
It's going to be of tremendous importance. Now, this is very important, generally, but extra important for WordPress. Now in WordPress ever since 2003, right up to the present day, your user name the first user that is created ated in WordPress, and is the administrator, the default name for that user was always admin ad m i n. And this made it extremely useful for hackers attempting a brute force attack. Remember, a brute force attack is where they try and guess your username and password. And they use the sophisticated software in order to find that out when it was just admin for 99% of users that made it extremely easy. And still today, there are many users that use admin as their username, but it's not that simple.
So you can see here my username for the admin is afternoon Zoey, how a little bit difficult to guess, but it's not perfect, and I will change it. Why? Have a look at this email. I recommend that you use the free version wordfence a security plugin for WordPress, which will do so many things for your website security, including blocking attackers attempting brute force attacks and other hacks and issuing new alerts for various security vulnerabilities on your site. And one of the options I suggest you enable when you're setting up wordfence is to get the weekly email of wordfence activity on your site because it shows you some very interesting activity that is happening, malicious activity. So here are some IPS that have been blocked for malicious reasons.
Maybe they're trying a brute force attack, or for any other reason. But here is very interesting, and this is what we're talking about. These are the usernames or some of them that have been used in attempted brute force attacks. Now of course, we're going to see the admin there. The admin username because that one will be the one that they try the most. And they've tried it and they see it doesn't work.
So they move on to the next username. There are also other generic WordPress usernames that they try like WordPress weblog or sites. Another one that's not here, I see a lot that they use a lot is test T S T. So that's a username that maybe hackers have had luck with in the past, and people use that as a username. And hackers can gain access to sites using that username. These are ones that you should not use, not every use. But there's much more than that.
It's much more than that. It should be so hard to get a look at this site. For example, this is the site that the email is coming from. I have wordfence on this site, and it's for a freelance bookkeeper. The first two words in the site title is freelance bookkeeper. So the software has gone in there and tried these two words.
Potential usernames. So you really have got to think outside the box. Even more than this. I can show you other emails that I've got where they've tried common first and last names, followed by a couple of digits. Can you believe that? So I've seen one like Miguel Rodriguez 54, or john Cooper 28.
So they are trying everything. It's nothing to them. They have these sophisticated software running on fast machines, they don't pay for the software, they don't pay for the electricity. It's nothing for them to just blast out these brute force attempts to any site. They don't care which site it is. They just want to hack as many sites as possible and make money.
So you really need to make your admin username hard to guess. And if you think your admin username isn't hard to guess, then you need to change it right now, and I'll show you how to do that in the next few videos. My name is Rob, covering I'll see you in another video.