• Resolved Martin1

    (@martin1)


    Hi,

    I don’t understand. I have it set to block every country except the Netherlands and Denmark but I just got a warning from WordFence stating:

    The Wordfence Web Application Firewall has blocked 100 attacks over the last 10 minutes. Below is a sample of these recent attacks:

    May 3, 2017 1:55pm 95.24.35.196 (Russian Federation) Blocked for Directory Traversal – wp-config.php in query string: fname=../../wp-config.php
    May 3, 2017 1:55pm 95.24.35.196 (Russian Federation) Blocked for Directory Traversal – wp-config.php in query string: file=../../../wp-config.php
    May 3, 2017 1:55pm 95.24.35.196 (Russian Federation) Blocked for Directory Traversal – wp-config.php in query string: download=../../../wp-config.php
    May 3, 2017 1:54pm 95.24.35.196 (Russian Federation) Blocked for Directory Traversal – wp-config.php in query string: download=../../../../wp-config.php
    May 3, 2017 1:54pm 95.24.35.196 (Russian Federation) Blocked for Directory Traversal – wp-config.php in query string: file=../../../wp-config.php
    May 3, 2017 1:54pm 95.24.35.196 (Russian Federation) Blocked for Directory Traversal – wp-config.php in query string: file=./wp-config.php
    May 3, 2017 1:54pm 95.24.35.196 (Russian Federation) Blocked for Directory Traversal – wp-config.php in query string: file=../../../../../wp-config.php
    May 3, 2017 1:54pm 95.24.35.196 (Russian Federation) Blocked for Directory Traversal – wp-config.php in query string: file=../../../../../wp-config.php
    May 3, 2017 1:54pm 95.24.35.196 (Russian Federation) Blocked for Directory Traversal – wp-config.php in query string: filename=../../../../../wp-config.php
    May 3, 2017 1:54pm 95.24.35.196 (Russian Federation) Blocked for Directory Traversal – wp-config.php in query string: file=../../../../../wp-config.php

    Why is iQ Block Country not blocking the Russian Federation?

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Author Pascal

    (@iqpascal)

    Because wp-config.php is not an actual page or post it can block.

    Under normal circumstances requesting wp-config.php will show an empty page.

    Apparently WordFence is blocking it. You could say so should iQ Block Country if you block the backend. For now it is not.

    Thread Starter Martin1

    (@martin1)

    Hi,

    I didn’t quit understand what you meant here:

    “Apparently WordFence is blocking it. You could say so should iQ Block Country if you block the backend. For now it is not.”

    WordFence just alerted me that at this moment, there is again an increased attack rate from the Russian federation.

    What do I need to do to keep them away? Block the front end as well? I have currently only blocked everyone from the backend.

    • This reply was modified 9 years ago by Martin1.
    Plugin Author Pascal

    (@iqpascal)

    iQ Block Country does not check for urls like “../../../wp-config.php or wp-config.php at all. If you’ve done a normal installation anybody who tries to get wp-config.php will receive a blank page.

    This plugin is designed to keep people away from either your backend, (part of) your frontend, or both. It’s not a real security plugin as WordFence is for instance. It will not check for file permissions or whatever security plugins can and should do. It is designed to keep your content from certain countries, or disallow them to retrieve the page so they can leave spam comments etc.

Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘Still not blocking’ is closed to new replies.