Attacks showing no user-agent
-
We run well over 100 WP sites on a dedicated server. We have tried every plugin from iThemes to Wordfence plus Cloudflare, moving login pages and double logins using .htaccess and ssh scripts to the root file .wpadmin to mitigate. Nothing seems to work on a particular issue.
I run a series of ssh commands every morning to see what is being attacked. Sometimes there are only 50 to 1000 against a few sites. Often there are 10’s of thousands against 1 or 2 sites on the server. None of the above mentioned techniques or plugins stop it. All come from 1 or 2 IP’s so we can easily block those but it is time consuming.
I recently logged into the cpanel and pulled up latest visitors so I could refresh and see if any of the techniques or plugins work and they do not. The attacks continue till I manually block the IP address. I also noticed the cpanel log for latest visitors does not show a user-agent. Does this mean they are using something other than a browser to hit that page? We even use a non standard port number for ssh (if that is they way they are trying to hit us) but that would require they hacked our server password which changes a lot.
If WordPress could come up with something like CPHULKE for WHM’s it would be great. That seems to work without any issues. We set the number of times an IP or Account can be attempted and it blocks them based on number of times or IP for the time period we set which is 6 months. That way you cover both kinds of brute force attacks and they can’t come back often.
Does anybody have an idea about how to stop something that does not have a user-agent? I tried a couple .htaccess codes but they did not stop it.
https://www.ads-software.com/plugins/all-in-one-wp-security-and-firewall/
- The topic ‘Attacks showing no user-agent’ is closed to new replies.