Skip to content
  • Security Tips
    • Delete Admin Account
    • Twitter Password Security
    • Stop Spammer WordPress Plugin
  • King’s College
    • Website
    • Culture, Media & Creative Industries
    • Term Dates
    • Virtual Tour
    • Wikipedia
    • Flickr
    • Facebook
    • YouTube
  • Pages
    • notes
  • Links 1
    • Aero
    • Alexis
    • Dallas
    • Edie
    • Elizabeth Taylor Swift
    • Isabella
    • Kimmy
    • Magdalena
    • Matt
    • Meg
  • Links 2
    • Nadya
    • Nostradamus
    • Obveeus
    • Paris LaRocque
    • Renie
    • Ryan
    • Sporty
    • Tiki
    • Tullia
    • Xue

Calendar

May 2025
M T W T F S S
 1234
567891011
12131415161718
19202122232425
262728293031  
« Apr    

Archives

  • April 2015
  • September 2013
  • July 2013
  • June 2013
  • April 2013
  • March 2013
  • December 2012

Categories

  • Haiku Speedbuild
  • Security Tips
  • Tech Dweeb
Xue FaithStudent, Gallerist, Webmaster, Host
  • Security Tips
    • Delete Admin Account
    • Twitter Password Security
    • Stop Spammer WordPress Plugin
  • King’s College
    • Website
    • Culture, Media & Creative Industries
    • Term Dates
    • Virtual Tour
    • Wikipedia
    • Flickr
    • Facebook
    • YouTube
  • Pages
    • notes
  • Links 1
    • Aero
    • Alexis
    • Dallas
    • Edie
    • Elizabeth Taylor Swift
    • Isabella
    • Kimmy
    • Magdalena
    • Matt
    • Meg
  • Links 2
    • Nadya
    • Nostradamus
    • Obveeus
    • Paris LaRocque
    • Renie
    • Ryan
    • Sporty
    • Tiki
    • Tullia
    • Xue
Xue Faith and other cast members wearing green "Poison" uniforms from fashion designer Jackie Graves, the faux-seriousness of the paramilitary uniforms being a visual metaphor for the real seriousness of wordpress security
Security Tips

WordPress Security: Delete Your Admin Account

On 16/12/2012 by Xue Faith

WordPress Security

I’ve been seeing a lot of bot login attempts on a number of different WordPress installs lately. Almost always (but not exclusively) they’re attempts to login to the account “admin”. There’s a pretty good chance you have a user with this name since WordPress often creates one when you initially do the install.

Xue Faith and other cast members wearing green "Poison" uniforms from fashion designer Jackie Graves, the faux-seriousness of the paramilitary uniforms being a visual metaphor for the real seriousness of wordpress security

I got to wear a sexy paramilitary uniform in this summer’s performance of VB41 – Rock the Casbah, who knew that a few months later I’d be giving WordPress Security tips! (WordPress security is definitely harder than virtual base jumping! 😛

So if you have the user “admin” and maybe a weak password, you could be ripe for break-in. I don’t actually know what the bots would do with your site if they got in, but it’s a safe bet they’re not trying to deposit cash in your bank account.

My advice: delete your “admin” account. Of course you need 1 or more “admin-instrator” level users, but none of them need that username. It might actually take you a minute to do this, since if you created the WordPress Install, you may well have
USER: admin
EMAIL: my.self@something.com
PASS: hopefullyNotSomethingReallyShort&allLowercase

This means that you won’t be able to create a new user account with your my.self@something.com email since it’s already in use. So if that’s your primary email, you’ll have to create a new admin-level user with a different email, then delete the “Admin” admin-level user, and THEN you can make
USER: meeeee
EMAIL: my.self@something.com

It’s a little bit of a nuissance, but we’ve all seen peeps, maybe ourselves, crying about data on a crashed hard drive, and thought, hmm, I guess backing up really isn’t that much hassle. Deleting a user named “admin” isn’t going to solve everything in the world, but it’s a pretty easy step to help diffuse a real and current problem. Shout if I can help or say anything more on it!


DISCLAIMER:

I’m way not any sort of security expert, nor a WordPress Security specialist, and since it’s pretty important stuff, as always, see a professional! This is just some info that might be useful as observed from my little mini-trench in the field.

Good Luck! Play Safe! But still Adventurous!

Tags: admin account, attack bots, password security, user accounts, user names, wordpress security

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Archives

  • April 2015
  • September 2013
  • July 2013
  • June 2013
  • April 2013
  • March 2013
  • December 2012

Calendar

May 2025
M T W T F S S
 1234
567891011
12131415161718
19202122232425
262728293031  
« Apr    

Categories

  • Haiku Speedbuild
  • Security Tips
  • Tech Dweeb

Creative Commons Attribution, Xue Faith, 2024. | Theme by ThemeinProgress | Proudly powered by WordPress