Viewing 6 replies - 1 through 6 (of 6 total)
  • Hi, Please watch the video tutorial on the following post to make sure you have setup that feature correctly:
    http://www.tipsandtricks-hq.com/all-in-one-wp-security-plugin-cookie-based-brute-force-login-attack-prevention-feature-5994

    Thread Starter wothers

    (@wothers)

    The instructions and video have shed no new light, it looks like I did everything correctly. Anyone reading this thread is welcome to test it.
    Please try all three links:
    http://www.kleinkaroobirdclub.org.za/?secrettest=1
    http://www.kleinkaroobirdclub.org.za/wp-admin/
    http://www.kleinkaroobirdclub.org.za/wp-login.php
    Thanks to anyone who reports back with results and browser used.

    Thread Starter wothers

    (@wothers)

    Odd, I can’t see my previous post when I use another browser where I’m not logged in?

    Thread Starter wothers

    (@wothers)

    Too many links maybe?
    I’ll try again…
    The instructions and video have shed no new light, it looks like I did everything correctly. Anyone reading this thread is welcome to test it.
    http://www.kleinkaroobirdclub.org.za/?secrettest=1
    Please also try wp-admin/ and wp-login.php
    Thanks to anyone who reports back with results and browser used.

    *UPDATE*
    See all my posts now – weird.
    Still appreciate it if someone can test it.

    Plugin Contributor wpsolutions

    (@wpsolutions)

    Hi,
    The feature works perfectly on your site.
    I tried your links and I am always being redirected when I try and access your login page or wp-admin directly.

    The reason why you are being redirected even when you are seemingly using the secret word is because your site’s URL as configured in WordPress does not have the “www” and you are trying to access your site using the secret word using an address with the “www” prefix. (Even though they point to the same domain, http://www.somesite.com and somesite.com are actually different as far as addresses go and are hence treated differently by the plugin)

    So if you try the following you will see that the feature works correctly and you will be able to access your admin login:

    http://kleinkaroobirdclub.org.za/?secrettest=1

    Now regarding the other behaviour you saw where you say it does not redirect you sometimes when you try accessing wp-admin directly – this is also normal behaviour and occurs because you probably already had the correct “secret” cookie in your browser as a result of having used your secret word once before, therefore the plugin has recognized this and will allow you through. Anyone else on the internet will not be allowed direct access because they will not have the required cookie.

    Having said that, I recommend that you now go in and change your secret word so nobody can access your login.php page 🙂

    Thread Starter wothers

    (@wothers)

    Thanks for the help.
    Not sure about the cookie thing or whether or not I use www or not.
    All I know is I can get into the site, but on my main computer the secret string redirects me and I have to use wp-admin or wp-login.php to log in, regardless of whether I use www.
    On another computer, where I have’nt used the secret string, I get redirected when I use wp-admin or wp-login.php
    It’s all very confusing, but it looks like it’ll do what it’s supposed to.
    As long as I can access the site, I’m happy.

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘Brute Force redirection’ is closed to new replies.