• I had added 3 usernames to immediately lock out. After a short period yesterday, it was working and showing each of these login attempts as blocked ( i.e. Paris, France was blocked by the Wordfence Security Network at …).

    However, today, the login attempts with the same usernames are failing even after I added an additional username to block. For example, one log says San Mateo, United States attempted a failed login using an invalid username “admin”.

    I specifically have admin and other usernames on my list.

    Have others experienced this? I searched the forum and found one post that said empty password logins do not get blocked, but that is all I can think of. I haven’t figured out how to check my logs to see if these are empty passwords.

    Thanks for any help you can provide.

Viewing 12 replies - 1 through 12 (of 12 total)
  • Plugin Support wfscott

    (@wfscott)

    @beantown123

    Thanks for writing in.

    Can you send over diagnostics to wftest @ wordfence dot com, via Wordfence > Tools > Diagnostics > Send Report by Mail. Please put your forum username in the second field there, and let me know here when they are sent.

    The users will be allowed to try to login again after the block expires, which is determined by the amount of time you have set in Wordfence > All Options > Rate Limiting > How long is an IP address blocked when it breaks a rule

    It is possible you saw them get blocked, then their block expired, then they again tried to log in with the name, got blocked, etc.

    I would set that to a few hours and then when you see a login attempt with a prohibited name, check the Wordfence > Firewall > Blocking area for that IP.

    Scott

    Thread Starter beantown123

    (@beantown123)

    Just sent it. Thanks.

    Plugin Support wfscott

    (@wfscott)

    Thanks, @beantown123.

    I am immediately blocked when I try to login with the name “admin” on your site. Go ahead and take a look at live traffic and let me know what you’re seeing. You’re likely seeing a New York IP. I was not able to view any pages after the block.

    You may want to adjust the lockout time I mentioned in the Rate Limiting area. If you want the block to be a few hours or a few days. Be sure to not set those rate-limiting rules too strict, however, or else you’ll be blocking good bots or visitors for multiple days (or whatever you set the lockout time to). Here is what we recommend for rate-limiting settings https://www.wordfence.com/help/firewall/rate-limiting/

    Scott

    Thread Starter beantown123

    (@beantown123)

    So I do see yours blocked, but others are not blocked.

    Here is yours:
    New York, United States left http://*******.com/ and was blocked by login security setting at http://********/favicon.ico
    12/5/2019 6:06:49 PM (2 hours 16 mins ago)

    Here is some that do not appear blocked:
    Clifton, United States attempted a failed login using an invalid username “admin”.
    Bulgaria attempted a failed login using an invalid username “admin”.

    Basically there are a bunch of failed logins with the usernames that should be blocked.

    Plugin Support wfscott

    (@wfscott)

    Thanks @beantown123

    Please screenshot some of the attempts for admin you are seeing that aren’t being blocked, so I can confirm.

    I appreciate your patience.

    Thanks,
    Scott

    Thread Starter beantown123

    (@beantown123)

    Hi, is there a way to send it securely to you since it lists my site info?

    Plugin Support wfscott

    (@wfscott)

    @beantown123,

    Sure, I apologize. You can send that to wftest @ wordfence dot com — please put your username here as the subject line and then post here to let me know it is sent.

    Thanks again,
    Scott

    Thread Starter beantown123

    (@beantown123)

    Hi, I sent it last night.

    Thread Starter beantown123

    (@beantown123)

    Hi no rush but I responded to your email a few days ago when you requested a screenshot.

    Plugin Support wfscott

    (@wfscott)

    @beantown123

    Thanks, I took a look for you. I sent over a request for one more confirmation/screenshot if you could give that a look, please.

    Thanks,
    Scott

    Thread Starter beantown123

    (@beantown123)

    Hi, just wanted to confirm you received my screenshot on 12/19.

    Thread Starter beantown123

    (@beantown123)

    Should I try reinstalling the plugin?

Viewing 12 replies - 1 through 12 (of 12 total)
  • The topic ‘Immediately lock out invalid usernames doesn’t seem to work’ is closed to new replies.