hooohn
Forum Replies Created
-
Problem remains after update…
please help
For the sake of completeness, this is the relevant Apache version:
2.4.6-45.el7.centos.4Does this match your expectation?
Basically yes, only this is about the blacklist, not the whitelist feature.
So you recommend to wait for the next bugfix release of the All In One WP Security & Firewall plugin?
Hi Patrick,
thank you for the quick reply!
The solution with the Members plugin worked – thank you! I added the ability
see_statify_evaluationto the standard user role.Best regards,
- This reply was modified 9 years, 3 months ago by hooohn.
… I will thx!
not sure if they stopped for good, nothing been logged for a couple of hours now
No, that’s the weird thing. It’s not about the “admin” user name but the actual administrator accounts user names which are different from the display names (and not all them publish posts anyway!).
I followed all the rules and configured WP accordingly:
- tables use different prefix, e.g. “xy_”
- no administrator account “admin”
- no user has matching display name and user name, especially not the administrators
example: 1. Administrator account display name: Fred. User name for Login: Peterexample: 2. Administrator account display name: Joe. User name for Login: Jimmy
Again, the attacking procedure:
- they tried to login with “admin” user name and got successfully locked out by the AIO WP S&F plugin
- After that, all real user names of administrator accounts were known, so they tried with “Peter” and “Jimmy” etc.
- They still got locked out after 3 times trying to login by the plugin, but somehow overcame the first levels of security.
How could they know all real administrator user names after the first round of lockdown?
Thanks again for looking into this – guidance highly appreciated! 🙂
ok thx.
What about the admin user names? how did they find out? they knew all real admin login names…?!
Hi, thx for the quick reply and sorry for the long pause!
I was busy because I suffered same kind attacks on all my sites plus (!) client sites 🙁
I did not have the pingback feature active, but changed it now and will monitor if new attacks happen.
The procedure of the hacker was as follows:
- Found out the renamed login address somehow
- tried to login with “admin” user name -> locked out by the AIO WP S&F plugin
- After that, ALL REAL ADMIN ACCOUNT NAMES were known and were tried on the login page. No other user names were tried out (did they have access to the database to find out or is there a security glitch with the plugin ???)
- all login trials lead to lockouts, so there was (hopefully, as far as I can see now) no successful login, though real admin names AND the renamed login address were known
I am a little bit desperate for I must tell clients what’s going on and I have no exact clue…
Any tipps are highly appreciated!!
thx
thank you – highly appreciated!
Hi mbrsolution,
thank you for the quick reply!
I need the double opt-in to confirm/verify the E-Mail address (EU law), the suggested Google-Plugin will not do that, unfortunately.
RPR-Plugin uses the %verification_url% shortcode within the registration E-Mail that already contains the renamed login url in the format:
http://blogname.de/renamed_login_url?action=verifyemail&verification_code=123xyz
So I think they did ok?!
Clicking on the verification link though results in a 404 error when the function in AIOWPS is active.
Thanks again for your help.
Cheers,
Robthx for your quick reply!
I don’t dare to do this on the live site right now as a brute force attack is currently running on my site 🙁
on my local mirror it works with Log-in lockdown and Basic Firewall turned off.