• Hi. My site is currently under attack from bots, hackers….etc…

    Since the WP-ZEP protocol has been activated via your plugin (THANK YOUUUU by the way, it’s a fantastic plugin), my library now is…well, it’s messed up. It’s a fantastic plugin, and I’m very happy to have it. But the Library is decidedly not in the best shape it’s been. :/

    The Library has a ‘comment button’…a sort of ‘pagination button,’ really (either description works) that’s showing, and won’t go away. It also is non-functional; you click it and it does nothing to sort the Library.

    And it’s covering up other information.

    When I mouse over that little button, it says: “(insert my site info here)…/wp-admin/upload.php?orderby=comment_count&order=desc&ip-geo-block-auth-nonce=…[insert some numbers here]” as a result. I’ve uninstalled your plugin (but checked the “remove all settings at uninstallation” box beforehand), then deleted it, then IMMEDIATELY reinstalled it (lol), then did 3 restore operations……nothing gets rid of it. I’ve even logged out as my own username and logged in as an alternate username I created, just to see if it was a user view setting I’d accidentally clicked. No luck.

    Thoughts?

    I’m including a screenshot below….hope that’s ok here. I know formatting is an issue sometimes; I think I pasted the right version for this forum, lol! 😀

    http://tinypic.com/r/ok8pyb/9

Viewing 6 replies - 1 through 6 (of 6 total)
  • Thread Starter eatandbemerry

    (@eatandbemerry)

    Oopsie. Looks like the system didn’t like that screenshot link, lol. SORRY! It’s now being held for 72 freaking hours because I pasted it wrong. GREAT. Now I have to worry abt it being a sign I was hacked AND getting in trouble with the Admins here for posting a freaking link, lol…dammmmittt, haha.

    SORRY!! Admins, just trying to get this issue resolved. I swear it’s not pr0n, or….something. Lol… 😀

    I hope to God this isn’t a time-sensitive issue that will crash my database that needs to get resolved now. Dammit.

    Thread Starter eatandbemerry

    (@eatandbemerry)

    OH THANK GOD it was approved lol.

    Okay, here’s my system info…and no, I’ve not run the debugger; I hope you won’t ask me to do that lol:

    SYSTEM INFO

    OS Type: Linux skymaster 3.2.61-grsec-modsign #1 SMP x86_64 (64 bit)
    Server Software: Apache
    CPU Cores: 8 Cores
    Load Average: 7.04, 7.35, 7.82
    Disk Space: 4.07 GB (18%) used of 23.14 GB total
    Database Size: 21.45 MB
    MySQL Version: 5.6.34-log
    Database Charset (Collate): utf8 (n/a)
    PHP Version: 7.0.24
    PHP Extensions: Core, date, libxml, pcre, sqlite3, filter, mbstring, SPL, PDO, Reflection, pdo_sqlite, hash, session, cgi-fcgi, bcmath, bz2, calendar, ctype, curl, dom, standard, ftp, gd, gettext, exif, iconv, imap, json, mcrypt, mysqlnd, openssl, pcntl, pdo_mysql, posix, pspell, mysqli, SimpleXML, soap, sockets, tokenizer, xml, xmlreader, xmlrpc, xmlwriter, xsl, zip, zlib, imagick, Zend OPcache
    Max Upload, Post Size (Input Vars): 100M, 105M (3000)
    Memory Usage: 16M (4%) of 400M (actual limit)
    WP Memory Limit: 400M (defined limit)
    WP Admin Memory Limit: 256M (defined limit)
    WP Debug: Disabled (no logging, display)
    Opcache Size (Max Files, Revalidate): 4M (3907, 2 secs)
    Page Cache (Plugin): Disabled
    Object Cache: Disabled

    Plugin Author tokkonopapa

    (@tokkonopapa)

    Hi @eatandbemerry,

    I’d confirm your issues including the post at ““Sorry, your request cannot be accepted” message at login”.

    1. The following means that you sometimes can not login because of the message, right?

    P.S.: that message (‘sorry, your request…’) appears when I sometimes go to activate a new plugin…but not when I’m logging in.

    When you’re logged-in and see the following page, then the secret token might be expired. In this case, please click “Dashboard”.

    Sorry message 1

    When you’re not logged-in and if you see the following page, then you might be blocked.

    Sorry message 2

    In this case, please refer to “What should I do when I’m locked out?” OR just delete/rename this plugin’s folder.

    2. Your media library looks like this:

    Media Library 1

    The CSS on your media library might be broken. But mine looks good and the pager button works fine:

    Media Library 2

    So I propose you to try “Grid view” instead of “List view”. But there is one drawback in “Grid view”. Please refer to “No image is shown after drag & drop a image in grid view at Media Library“.

    I guess something conflicts with my plugin. So please let me your theme and plugins you adopt. The list can be available from “Debug information” at “Plugin settings” on “Settings” tab like this:

    debug information

    Thank you for your cooperation to solve the issue.

    Thread Starter eatandbemerry

    (@eatandbemerry)

    thank youuuu!

    responses:

    1.] i never get the message ‘your request cannot be accepted’ at any other time than when i’m already logged in….so thankfully that means i’m not blocked. so i’m guessing, based on your responses, that’s only going to appear when the system doesn’t recognize i’m ‘me’ — an admin. perhaps it’s the site overloaded at the time with its memory being focused on activating the new plugin i’m trying to activate when i get that message…and as a result, your plugin can’t access the folder where my identity is. so it doesn’t recognize i’m ‘me.’ all the memory resources are taking up the memory resources that your plugin would normally have….just a guess, but perhaps that’s it!

    2.] if it is merely the CSS in my library…THANK GOD. then i assume that means i just need to reinstall whatever CSS file the library uses, right….? please tell me that’s it. otherwise, i was considering a total wipe and reinstall… :/

    3.] i’m currently just coming out of a brute force attack (which your plugin helped deter — had several WP-ZEP blocks you did, thank you!) and do not want to post too much about my site online…would be happy to give you the plugins list you asked for, but privately. so, please tell me how to get you that info; it makes me insecure to post that much information here.

    4.] i was amazed that i wasn’t getting attacked anymore by a ‘brute force attack’ lol and with the library error…last night i was terrified my install of IP Geo Block plugin was somehow damaged from all the reinstalls and whatnot i’ve done recently. nothing was coming up as trying to hack my site anymore! hahaa…so. i deactivated, deleted [had the ‘remove all settings’ option checked before i did]….then did a fresh install of the plugin again. and today i wake up and find two attempts were made. strange thing, though: i had put all my same settings up as before, including the country block. china was on that list. and a chinese IP got through — they only accessed the ‘public’ folder, but still….guessing that they are trying to see what my site is made up of so they can attack later. vulnerabilities, plugins, version of wordpress….etc. HOW is this possible? i thought all IPs from a country are blocked when i put a country on the block list. how is any CN address not immediately blocked, no matter how/where they access my site?? i want all CN traffic blocked! 🙁 please tell me how this is possible. i was stunned….

    Plugin Author tokkonopapa

    (@tokkonopapa)

    Hi @eatandbemerry,

    1.] i never get the message ‘your request cannot be accepted’ at any other time than when i’m already logged in….

    OK, good!

    2.] if it is merely the CSS in my library…THANK GOD.

    I’ll check the plugins and theme you install if those are available for free.

    3.] i’m currently just coming out of a brute force attack…would be happy to give you the plugins list you asked for, but privately.

    Sure, please email me at tokkonopapa at yahoo dot com.

    4.] i was amazed that i wasn’t getting attacked anymore by a ‘brute force attack’ lol…including the country block. china was on that list. and a chinese IP got through — they only accessed the ‘public’ folder, but still….guessing that they are trying to see what my site is made up of so they can attack later….i want all CN traffic blocked!

    I think it might be cause by “UA string and Qualification” in “Front-end target settings” section. Please refer to this document.

    And please try to add *#CN at the top of the list like this:

    UA string and qualification

    Plugin Author tokkonopapa

    (@tokkonopapa)

    Hi @eatandbemerry,

    A happy new year! I hope you are doing well.

    But I’m afraid that your first issue (breaking css in media library) is still there, if you’re still in use of my plugin.

    I’d appreciate you if you let me know about your “Debug information” in “Plugin settings” by sending email to tokkonopapa at yahoo dot com. I’ll try to reproduce your issue in my test environment.

    Thank you for your cooperation to improve my plugin.

Viewing 6 replies - 1 through 6 (of 6 total)

The topic ‘Bizarre WP-ZEP “Feature”…? Library view/format issue.’ is closed to new replies.