Other than educating users about good passwords, regular updates, "limit login" plugins etc, what techniques are hosts using to limit attacks against their customers Wordpress blogs.
We've seen huge waves of wp-login.php attacks over christmas, and we can see constant "slow" Brute Force attempts now, which mod_sec rules just don't see.
Luckily cloud linux, stopped the boxes from getting anywhere near crashing, but performance of a number of our servers became sub optimal for a while.
Any further techniques would be greatly appreciated.
We've seen huge waves of wp-login.php attacks over christmas, and we can see constant "slow" Brute Force attempts now, which mod_sec rules just don't see.
Luckily cloud linux, stopped the boxes from getting anywhere near crashing, but performance of a number of our servers became sub optimal for a while.
Any further techniques would be greatly appreciated.