WordPress.org

Ready to get started?Download WordPress

Forums

All In One WP Security & Firewall
[resolved] Display Generic Error Message (8 posts)

  1. reedycat
    Member
    Posted 11 months ago #

    "Check this if you want to show a generic error message when a login attempt fails" doesn`t work. Errors are being displayed in any case.

    http://wordpress.org/plugins/all-in-one-wp-security-and-firewall/

  2. wpsolutions
    Member
    Plugin Author

    Posted 11 months ago #

    When the feature is enabled what is the exact error message you are getting when your login attempt fails?

    The errors displayed when you enable the "show a generic error message when a login attempt fails" checkbox will be generic in nature.

    For example if someone who attempted to login gets the username or password wrong the message displayed will be the same regardless, ie, it will say:
    "ERROR: Invalid login credentials"

    Normally without this feature you would get a message telling you which of the fields you got wrong - eg, "Error: Invalid password"

    The value of this feature is that it hides which part of the login fields were wrong hence making it harder for the hacker to know whether they should be targeting just the username or password or both.

  3. reedycat
    Member
    Posted 11 months ago #

    Its ok then. I thought that option must totally disable any error messages while unsuccessfull loginning - wouldnt it be better? Anyway, it`s exellent plugin, thanks.

    p.s. I`m going to finish making russian language files today for the All In One WP Security & Firewall - may I send it to you?

  4. wpsolutions
    Member
    Plugin Author

    Posted 11 months ago #

    Yes certainly and thank you.
    Please get in contact with us using the following link and we can include your file in the next release of the plugin:
    http://support.tipsandtricks-hq.com/contact

  5. reedycat
    Member
    Posted 10 months ago #

    I`ve sent my email at http://support.tipsandtricks-hq.com/contact
    do reply, please, I could send you the russian lang files.

  6. mra13
    Member
    Plugin Author

    Posted 10 months ago #

    @reedycat, I did reply to your email. Your email actually landing in my spam box at first. So I won't be surprised if my reply went to your spam box.

  7. Jonas Lundman
    Member
    Posted 4 months ago #

    This checkbox is confusing, concider a better labeling. On - the default "normal" way is in use, correct?

    It sholud be the opposite - changes to wp default by the plugin should be checked.

  8. wpsolutions
    Member
    Plugin Author

    Posted 4 months ago #

    Hi @Jonas Lundman,
    To make it clearer we will add an explanation in the description part of that checkbox.

    Basically, if you leave that box unchecked, it will tell the person who is trying to log in which field was entered incorrectly.
    Example:
    ERROR: Invalid username

    If you enable that checkbox, the message will be:
    ERROR: Invalid login credentials

    The above "generic" message will make it harder for the hacker to guess which login field they have entered correctly or incorrectly.

Reply

You must log in to post.

About this Plugin

About this Topic

Tags

No tags yet.