mbrsolution on "[Plugin: All In One WP Security & Firewall] Instantly Lockout Invalid Usernames not preventing multiple attempts"

ساخت وبلاگ

Hey there!

Actually, if I go to Dashboard -> AIOWPS Logs and select the log files there in the dropdown, I get the "Log file is empty!" error. I've been tracking activity on the site via another plugin currently. Not sure if there's something we can do to enable the logs (we're on Rackspace Cloud Sites hosting, if that helps)?

The IP address that was trying yesterday to get in (it changes every few days, as I think it's directed via bots) was 195.154.237.108. Unlike most of the other bots we've seen thus far, it wasn't just blindly hammering at the "admin" useame with multiple passwords (although that was its first attempted useame) -- it was trying out multiple invalid useames that relate to our domain name (luckily, our admin useame is not easily guessed).

Here's two of the 10 entries from that particular set of attempts yesterday, with some information redacted ("oururl" substituted for our actual domain name):

France attempted a failed login using an invalid useame "wwwoururlcom". http://oururl.com/wp-login.php
5/5/2016 4:44:25 AM (5 hours 32 mins ago) IP: 195.154.237.108 Hostname: 195-154-237-108.rev.poneytelecom.eu
Browser: IE version 9.0 running on Win7
Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)

France attempted a failed login using an invalid useame "[email protected]". http://oururl.com/wp-login.php
5/5/2016 4:44:24 AM (5 hours 32 mins ago) IP: 195.154.237.108 Hostname: 195-154-237-108.rev.poneytelecom.eu
Browser: IE version 9.0 running on Win7
Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)

The AIOWPS Dashboard display of temporarily locked out IPs at the time read:

195.154.237.* 0 Admin login_fail 2016-05-05 03:44:15 2016-05-06 03:44:15

I have not been using the Blacklist Manager on this yet because it's the "Instantly Lockout Invalid Useames" functionality that seems to be not actually locking them out (again, trying to help troubleshoot the problem -- I could easily lock them out using the Blacklist Manager but that might confuse the issue). I have the instant invalid useame lockout set to lock out for a full 24 hours.

I could take this to email for troubleshooting if you'd prefer, just let me know. Thanks!

WordPress ...
ما را در سایت WordPress دنبال می کنید

برچسب : نویسنده : استخدام کار wpss بازدید : 98 تاريخ : شنبه 18 ارديبهشت 1395 ساعت: 7:18