• Resolved bluemi

    (@bluemi)


    Is it possible that Wordfence is pushing its Pro Version a bit too much? I keep getting notifications about “Increased Attack Rates” at least twice a day, and all of the attacks are allegedly coming from IP’s in Singapore. However, in the logs there is nothing about attacks, and the mentioned IP’s don’t even appear. Something seems to be wrong here.

    • This topic was modified 4 months ago by bluemi.
    • This topic was modified 4 months ago by bluemi.
Viewing 1 replies (of 1 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @bluemi, thanks for getting in touch.

    Increased attack rates aren’t a prompt to upgrade, the heightened activity mentioned could be occurring with the Premium version of the plugin installed too. Wordfence’s firewall (WAF) will often use its extensive database of vulnerabilities, “bad” IPs and signatures to make a block before they reach other settings like Rate Limiting, Brute Force, etc.

    The “increased attack rate” emails are triggered by attacks that break WAF rules in the “Rules” list on the Firewall Options page, and the global IP blocklist.

    I’m not sure whether you’re checking access logs for the server, or Wordfence’s Live Traffic page when you say, “IPs don’t even appear”. If you could provide an example screenshot or forward of the email to wftest @ wordfence . com that shows the Singapore IPs, we can take a look at whether they appear on our global blocklist. Make sure to mention your forum username in the subject so we can find it and respond here after you’ve sent it.

    Thanks,
    Peter.

Viewing 1 replies (of 1 total)
  • You must be logged in to reply to this topic.