• Resolved dasher0074

    (@dasher0074)


    Hi,

    I’m receiving this kind of emails from Wordfance. Should I worry about this? When I checked this IP in Live traffic shows that is “Human” not a bot. I receiving many from different locations.

    This email was sent from your website “Matau. Girdžiu. Gyvenu.” by the Wordfence plugin at Friday 3rd of February 2023 at 11:12:02 AM
    The Wordfence administrative URL for this site is: https://www.optikospasaulis.lt/wp-admin/admin.php?page=Wordfence
    The Wordfence Web Application Firewall has blocked 177 attacks over the last 10 minutes. Below is a sample of these recent attacks:3 vasario, 2023 9:06am  194.110.115.212 (Belgium)     Blocked for Known malicious User-Agents
    3 vasario, 2023 9:06am  194.110.115.212 (Belgium)     Blocked for Known malicious User-Agents
    3 vasario, 2023 9:06am  194.110.115.212 (Belgium)     Blocked for Known malicious User-Agents
    3 vasario, 2023 9:06am  194.110.115.212 (Belgium)     Blocked for Known malicious User-Agents
    3 vasario, 2023 9:06am  194.110.115.212 (Belgium)     Blocked for Known malicious User-Agents
    3 vasario, 2023 9:06am  194.110.115.212 (Belgium)     Blocked for Known malicious User-Agents
    3 vasario, 2023 9:06am  194.110.115.212 (Belgium)     Blocked for Known malicious User-Agents
    3 vasario, 2023 9:06am  194.110.115.212 (Belgium)     Blocked for Known malicious User-Agents
    3 vasario, 2023 9:06am  194.110.115.212 (Belgium)     Blocked for Known malicious User-Agents
    3 vasario, 2023 9:06am  194.110.115.212 (Belgium)     Blocked for Known malicious User-Agents

    Best Regards,
    Damian

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @dasher0074, thanks for getting in touch.

    You shouldn’t necessarily worry as Wordfence is handling these blocks by the looks of things, but it’s alerting you to the fact that your site has had a large increase in attacks that may require further attention if they persist. The plugin does all of the important blocking for you to avoid implementing a manual blocking regime – which can be time consuming to keep up with current IP ranges etc.

    However, I also understand that if your site is being hit quite hard or often by the same IP, you might want to try stopping that. As you already know the IP, you could copy or manually type it into the Wordfence > Blocking page under “Block Type: IP Address” when alerted in this way.

    Seeing this alert might also just prompt you to double-check your Rate Limiting Rules on the Firewall Options page. This configures how crawlers and humans are treated.

    I generally set my Rate Limiting Rules to these values to start with:
    Rate Limiting Screenshot

    • If anyone’s requests exceed – 240 per minute
    • If a crawler’s page views exceed – 120 per minute
    • If a crawler’s pages not found (404s) exceed – 60 per minute
    • If a human’s page views exceed – 120 per minute
    • If a human’s pages not found (404s) exceed – 60 per minute
    • How long is an IP address blocked when it breaks a rule – 30 minutes

    I also always set the rule to Throttle instead of Block. Throttling is generally better than blocking because any good search engine understands what happened if it is mistakenly blocked and your site isn’t penalized because of it. Make sure and set your Rate Limiting Rules realistically and set the value for how long an IP is blocked to 30 minutes or so.

    With Brute Force settings, I recommend trying 3-5 for attempts and password resets, counted over 4 hours, with a 30 minute (or longer) lockout time period.

    Remember there is no hard and fast, one size fits all set of rules for every site. This is just a good place to start. During an attack you may want to make those rules even stricter. If you see visitors, like search engine crawlers getting blocked too often, you might want to loosen them up a little.

    Here is a video guide to Rate Limiting as well: Rate Limiting Guide

    I hope that helps you out!
    Peter.

    Thread Starter dasher0074

    (@dasher0074)

    Hi,

    Thank you for your answer. I will try your recommended setup of Rate Limiting.

    Best Regards,
    Damian

    Plugin Support wfpeter

    (@wfpeter)

    No worries @dasher0074, always happy to help out.

    As Wordfence is an endpoint firewall, it catches, restricts and blocks users before the point your site tries to host content to them (when optimized) but cannot stop them attempting to access your site. Restrictions from the server’s end are possible to block IPs before PHP runs, if your host offers them.

    Thanks again,
    Peter.

Viewing 3 replies - 1 through 3 (of 3 total)

The topic ‘Increased Attack Rate’ is closed to new replies.