• Resolved dds

    (@dixonds)


    Hello. I have created buttons out of images with links. They take the visitors to posts or pages in either the main root domain or one of several subdomains. All the subdomains use exact copies of the header and footer from the main root domain so they all look the same. This is a brand-new site, my first.

    I set up All-In-One Security on the main root domain and all the subdomains, with identical settings. All the Basic features are enabled, but I followed the advice and avoided most intermediate and advanced settings. The Intermediate settings enabled are — users: Disable Application Password; database: Database Prefix; brute force: Login Form Honeypot and Registration Form Honeypot; scanner: File Change Detection. The Advanced settings enabled are — firewall PHP rules: Proxy Comment Posting, Bad Query Strings, and Advanced Character String Filter.

    Now, the image buttons display and function properly in the main bodies of the pages, but are not displayed in the headers and footers, only an image placeholder and the Alt Text. Can you tell me is this an issue with the security somehow and if so, what setting(s) might be causing it? Why would it only affect the Headers and Footers? Also, if I try to track it down by switching one feature at a time, how long do I have to wait between switching it and viewing the site, to be sure the switch has taken effect?

    Thanks.

    The page I need help with: [log in to see the link]

Viewing 9 replies - 1 through 9 (of 9 total)
  • Plugin Support hjogiupdraftplus

    (@hjogiupdraftplus)

    Hi @dixonds

    I can see the domain used for image is dds.dixonsforum.com which might be an issue due to prevent image hotlinking.

    Do you have the WP Security > File security > File protection tab – Prevent Image hotlinking feature on. Please disable it once and cross check if it solves the issue.

    If still an issue let me know.

    Regards

    Thread Starter dds

    (@dixonds)

    Yes, thank you, hjogiupdraftplus, I did try that already and that’s why I was asking about the time lag about how long the updates take place. So, have I made a mistake by copy-pasting the header images from dds.dixonsforum.com to dixonsforum,com and the other subdomains? Does WordPress automatically hotlink them instead of copying? If that is the issue I may have to rebuild the headers by hand for each subdomain, right? I will disable hotlink blocking and see how that works. Thanks, I will let you know.

    Thread Starter dds

    (@dixonds)

    That seems to have done the trick. So, apparently, when I copy-paste the header-footers from one domain to another, WordPress just automatically hotlinks the images rather than copying them whole. If I want the hotlink blocking active, I will need to rebuild the header-footers for each domain from images in their own media libraries, correct?

    Plugin Support hjogiupdraftplus

    (@hjogiupdraftplus)

    Hi @dixonds,

    Yes you might need to rebuild the header and footer to use the image from the same site domain ( subdomain) as image prevent hotlinking try to match it.

    Right now if you have the WordPress home URL set start with www. instead just https://dixonsforum.com/ check from Settings > General settings it should alos work as it will allow wildcard http(s)?://(.*)?dixonsforum\.com

    https://snipboard.io/iWhjwI.jpg

    Regards

    Thread Starter dds

    (@dixonds)

    Actually, I have been typing that www. in by hand, because the SEO documentation says the Googlebots like it better. I have been looking for a way to make it automatic. So you’re saying all I have to do is go to AdminPanel>Settings>General and change the WordPress Address (URL) field and the Site Address (URL) to https://www.dixonsforum.com, and the www. will be automatically inserted into all the links? Or do I just change one of the fields, and if so, which one?

    I am planning on rebuilding the headers and footers without the image hotlinks, so I can disable hotlinking, and would rather have the www. in all the links, since the SEO advises that is better.

    Thread Starter dds

    (@dixonds)

    On the site lockout question, yes, I did go back to the site through the Hostinger Dashboard, and indeed it is set up for lockout after three failed attempts. So, if it locked me out after only one attempt, does that mean a hacker is trying to get in already? The site isn’t even pinging the Googlebots yet.

    Thank you for the code snippet screenshot. Sadly, it doesn’t help me understand. I chose WordPresss because their literature all says no need to know code, and I don’t. But not unwilling to learn it, but don’t know it now. When I get all these subdomains and plugins co?rdinated and the site is functioning satisfactorily I will pause and study the coding. From what I can gather there are like five languages to learn – HTML, PHP, CSS, JavaScript, JSON, XML, and maybe another one or two more and maybe dialects. I wanted to get the sit up and running without coding like the site builder pitches say, but to do some of the fancy stuff it would indeed be better to know the code.

    Plugin Support hjogiupdraftplus

    (@hjogiupdraftplus)

    Hi @dixonds,

    Yes, Going to Admin Panel > Settings > General and change the WordPress Address (URL) field and the Site Address (URL) to?https://www.dixonsforum.com, and the www. will be automatically inserted into all the links.

    But if you are not technical person do not do that instead rebuild the the header / footer – changing images to use from that site’s media gallery ( with same domain ).

    That code snippest only to know your the site URL is not having www. currenly do not required to know more details of it and not required to know the languages to use AIOS plugin also.

    Hostinger dashboard if you try access and locked out only if after one attempt. It is due to the AIOS plugin only if WP security > User security > login lockout is enabled and Instantly lockout invalid usernames: is on and trying with invalid username it might block immediately.

    Regards

    Thread Starter dds

    (@dixonds)

    So, I set it to give three login attempts before lockout, and there’s a typo in the first attempt, so it calls that an invalid username, and the second attempt has no typo but it locks me out anyway, is what it seems like you’re telling me. Is that really how it works?

    On the www. thing, when I change my general settings to include the www. , my site logo image becomes an unrecognizable blob, and my media library becomes nothing but blank squares. I can click on the squares and it will display their filenames, so I can discard and replace the site logo in general settings, but it still appears as an unrecognizable blob. Not sure how the images display on the pages though.

    When I remove the www. from the url in General Settings, the media library and site logo display return to normal. Please tell me now, before I get much more work done, do I have to restart from scratch to get the www. into the url? Or is there a way to put it there without completely messing up the media library? And, if I do start from scratch, will it even work then or will it still interfere with the images like this? Thanks.

    Also, if I disable the AIO Security plugin and re-enable it, does it remember all my settings or do I have to re-do them all? Thanks again.

    • This reply was modified 5 months, 4 weeks ago by dds.
    Plugin Support hjogiupdraftplus

    (@hjogiupdraftplus)

    Hi @dixonds,

    Yes, If you have 3 invalid login attempts and instantly lockout invalid user name. if you do first invalid username attempt and then thought correct username and password entered you will be locked out and will show message.

    ERROR: Access from your IP address has been blocked for security reasons. Please contact the administrator.

    Ok, it might be before changing the www. you have remove image prevent hotlink is still on in the htaccess urles which suppose to disable showing image for all you should disable that rule first and cross check.

    If adding www. is problem better you user proper image urls (not using dds.dixonsforum.com) in header / footer.

    Yes if you deactivate and reactivate the AIOS plugin. It will remember all settings.

    If you Delete after deactivate it will delete all settings. You can export settings WP Security > Settings > Import/Export before deactivate + delete so at any time you can import those.

    Regards

Viewing 9 replies - 1 through 9 (of 9 total)
  • You must be logged in to reply to this topic.