Been appreciating the 404 Event Logs feature. I can have visibility on attempts of exploits from suspected (malicious) IPs. One thing I would like to request though.. Is it possible to do blocking via subnet (/24) instead of individual IPs?
Thank you!
]]>First of all, I’d like to congratulate you on a fantastic plugin, probably the best and/or most important of them all. Big kudos!
I have the setting “Always block entire subnet Class C of intruders IP” enabled, which has saved me hours of time. So I am grateful for that particular feature.
However, today a subnet was blocked that I would like to unblock. Is there a way to do that without resetting the plugin?
When a user has a certain number of failed logins, I have it set to “Always block entire subnet Class C of intruders IP”. Where does it put this IP address’ subnet?
I cannot find that IP subnet anywhere. It’s not in the Access List “Black IP Access List”, and it’s not in the “Lockouts”. It’s almost as if it did nothing with the IP at all. It is also not in the DB table “cerber_acl”.
]]>Here goes- I have a site that was initially running Securi as it’s security plug-in. Everything was running fine, it had log-in.php hidden and it emailed me whenever I or one of the four editors on the site logged in succesfully. Not a problem at all been up and live for about six months without a concern. Until last night.
I checked my email at about midnight to find a BRUTE FORCE attack email from them, listing a load of IP addresses. I went in to check and see what I could do, to find the Firewall section is only available in the Pro section so had to have a bit of a work-around (It’s for a massively under-funded charity, we simply don’t have the funds to pay out what Securi where charging)
No problem, I came across you guys. I’ve installed and set everything up as securely as I think I can..
My main concern is thus- since about 3AM this morning until now (19:50 GMT) I have since had 549 emails, all subnet blocks or attempting to access wp-login. Am I panicking without cause, or is this not “normal” behaviour? The site is running fine and nothing untoward is seeming to have happened barring this sudden onslaught of attacks. Is this a common thing or have I need for worry?
My main concern is that if these blocks are all heading towards a 404, will this eventually cripple my bandwidth?
Thanks for reading. Hopefully someone can put me out of my misery here.
Andy
https://www.ads-software.com/plugins/wp-cerber/
]]>Can it be done? Has it been done? How is it done?
I’m sorry if there’s a blatantly obvious way of doing this, but I missed it and google isn’t helping me much…
TIA
]]>https://www.ads-software.com/plugins/stop-spammer-registrations-plugin/
]]>https://www.ads-software.com/plugins/stop-spammer-registrations-plugin/
]]>After upgrading to 3.1 I’ve had a couple problems –
This has the net effect of making those networks more or less useless. I may have misunderstood something critical – are multi networks technically a hack/unsupported thing/bad idea? I upgraded to 3.1 when I saw the “network” enhancements, assuming mistakenly that multi-networks would get a boost, but it’s been… well, I already said.
Our server is setup to host sites following the format:
https://wp.school.edu/{username}
For a pilot project with the art school, we want to set up eportfolio sites under the url:
https://wp.school.edu/artSchool/designDept/eportfolios/{username}
In theory, I would prefer if
https://wp.school.edu/artSchool/designDept/eportfolios was a subnet of
https://wp.school.edu/artSchool/designDept/ which was a subnet of
https://wp.school.edu/artSchool/ a subnet of
https://wp.school.edu/
And that any of those subnets could have sites within them.
So here’s where I am:
Is this a limitation of the plugin and/or wordpress? Or is it possible that it can be done, just that I’l need to write a more complicated htaccess file?
* it may seem a bit old school (ha ha) to want to retain the hierarchy, but many of the use cases are things like an instructors information page, or student assignments, etc. We partially want to use multinetworks as a way to manage templates & settings for different schools & departments, and partially as a structural organizer (we have like 15 colleges and hundreds of departments, all of which have different programs, many with similar names – for example there are several different colleges with a department that is referred to as “communications” but is actually called communication therapy or science or blah blah blah – you get what I’m saying, I’m sure)
]]>