[Sophie_Young]where your credentials could be sniffed as you enter them into the page? couldn't anyone just scan for wordpress config interfaces on random domains and take over websites? my understanding is that this installation is supposed to be completed on a machine attached to a secure LAN, but I'm installing wordpress on a VPS