• It’s the second or third time I’m locked out of my site. I followed the instructions provided here, but no luck.

    The itsec_lockouts in phpMyAdmin is empty.

    The itsec_log shows 17 login attempts in 3.5 min, coming from my ip address, all shown as brute force/invalid login attempt. In reality, I only tried 3 times, each time the WP login form was returned blank with a blank error field on top with a red left-margin (yes, login error messages have been disabled in the iTheme Security settings). And after each of the 3 times I re-entered the blank form (which probably registered as a second attempt, but still far fewer than 17…) which proves to work on another site where I’m often unable to get in the first time but it always works on the second time I hit enter (with the blank form).

    I then looked at the itsec_temp table and saw my ip address, several times. I couldn’t find any explanation on the purpose of this table but I proceeded to delete the records thinking they are what keeps me out, but was still unable to proceed.

    And, yes, the same (unchanged) ip address is white-listed in the plugin settings.

    Might this have anything to do with my having set up Jetpack on the site (for testing purposes)? I don’t have it on the site where iTheme Security works fine.

    And how do I get back in without restoring the database to a much older version, before ITS was installed? I really like this plugin, and it helps withhacking attacks my sites had, but I’m a bit tired of having to reinstall the site after I get locked out.

    Thanks!
    JF

    https://wordpress.org/plugins/better-wp-security/

  • The topic ‘Locked out of my site with false "brute froce"’ is closed to new replies.