Auth failures from 127.0.0.1 (varnish?)
-
All hack attempts on my admin page are being logged as coming from 127.0.0.1. I expect this is because I’m using the Varnish cache to front my Apache.
I believe Varnish honours the proxy convention of passing the source IP in the X-Forwarded-For header. The wp-fail2ban plugin should look for and use this header if the source IP is 127.0.0.1.
Please double-check my assumptions for security vulnerabilities (i.e. the client should not be able to set X-Forwarded-For to mislead wp-fail2ban).
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
- The topic ‘Auth failures from 127.0.0.1 (varnish?)’ is closed to new replies.