• I have set my lockout duration to 1 day, however when I look at my Live Traffic view, the same address is locked out numerous times only seconds or minutes apart. If they are actually blocked, how are they incurring another block if they can’t access the site to begin with?

    Not sure it matters, but it’s showing as a human, not bot.

    Hoping this is normal behavior and that they haven’t found a way around the block.

    Thanks for any assistance.

Viewing 7 replies - 1 through 7 (of 7 total)
  • Hi @jderosa,

    There’s two different types of attacks, and they use different block durations.

    Amount of time a user is locked out controls how long a user is preventing from logging in, or using the password recovery form. (Note this will still allow them to browse the site normally)

    How long is an IP address blocked when it breaks a rule controls how long a user is blocked from accessing your site.

    The second duration is found under Brute Force: https://i.imgur.com/adFoeNJ.png

    Dave

    Thread Starter jderosa

    (@jderosa)

    Thanks. I have the user lockout set to 2 months. I have the IP block set to 1 day.

    These are people trying to access xmlrpc.php, which I have explicitly blocked.

    How do I see them accessing it 3 minutes apart?

    What is this URL that you put for Immediately block IPs that access these URLs in Wordfence settings?

    Or did you block xmlrpc using another method?

    Dave

    Thread Starter jderosa

    (@jderosa)

    /xmlrpc.php

    It appears to be working. I get an entry that says that the user was blocked for having accessed a forbidden URL, but then lets them do it again 2 minutes later.

    Thread Starter jderosa

    (@jderosa)

    Hi again,

    Any suggestions? Same user appears to be still able to attack repeatedly. 12 times within the last hour, even though my How long is an IP address blocked when it breaks a rule is set to 1 day.

    Thread Starter jderosa

    (@jderosa)

    Thread Starter jderosa

    (@jderosa)

    Hello, Dave,

    Sorry to be a pest, but any suggestions? I’m concerned that I have something misconfigured, but it seems that this is just how it works.

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘Live Traffic shows blocked IPs continue to attack’ is closed to new replies.