• Resolved kristinubute

    (@kristinubute)


    Hi

    I recently installed your plugin and using the Live View to view potential hacks and failed logins and bots etc.

    As there are quite a few things that show in here, I’m just needing to understand some of them, when a particular IP from another country shows that it tried to access a particular file …

    Some say bot, some say other. Here is an example below.

    domainname.com.au/wp-includes/simplepie/content/radio.php

    14/12/2023 10:49:02 am (17 minutes ago)

    IP:5.45.80.13Hostname: free.ispiria.net

    Human/Bot:Bot

    Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.141 Safari/537.36

    This is in Russia

    So does this mean that its a dodgy Bot trying to access particular file radio.php that may be there, OR they randomly target websites with this to see if it has been compromised?

    Our client site had some files changed approx 1 month ago, we cleaned it completely up, and installed your plugin.

    Your plugin has been very helpful in stopping these people and I’m just viewing it regularly now and BLOCKING IPs and IP ranges accordingly and putting them on PERMANENT block.

    So just I have a few things to understand when watching the LIVE VIEW.

    ALSO with some Bots that need to access the website to rank certain pages or products of an ecommerce store, HOW can I ensure I DON’T accidentally BLOCK an actual bot for rankings in google, compared to the OTHER type of BOT it says in the description which I assume are dodgy bots trying to access certain files in the backend?

    Also the LIVE VIEW doesn’t show all the times and days throughout the day. Obviously I can’t have the website tab in the backend OPEN all the time in the backend. So if I’ve checked in the morning 10am and then left the tab open, but then go back later in the day at 8pm to that same tab, it will NOT show all transactions in between of potential threats etc.

    I obviously want to see ALL potential threats etc and block certain IP’s that could be a problem, so we DON’t have the issue again for my client site.

    Is there an issue with my LIVE VIEW, as I thought I should be able to go back and view from say 8pm and keep scrolling down to earlier in the day and view ALL in the LIve view at different times of the day.

    Thanks

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @kristinubute, thanks for your message.

    As I explained before, IPs frequently will randomly target websites to see if something can be exploited without any prior knowledge of the platform or plugins installed beforehand.

    You don’t need to constantly keep an eye on the data as Wordfence is blocking the important traffic so you don’t have to. We generally consider a manual blocking regime time-consuming and unnecessary, but it’s good to check in with Live Traffic to stay generally informed.

    Your question about legitimate bots is explained in my post here: https://www.ads-software.com/support/topic/viewing-live-view-and-understanding-the-breakdown/#post-17276745

    Live Traffic shows “SECURITY ONLY” as default rather than “ALL TRAFFIC” as the amount of data held is significantly increased, but isn’t necessarily useful. For busy sites, there would be many successful page loads and other normal actions you don’t need to monitor to filter through. There’s no issue with yours by the sounds of things, but if you change it to “ALL TRAFFIC”, past data won’t be reflected, only traffic from that moment onwards. I don’t recommend you change this.

    Your scans should keep you on top of any critical or high severity warnings. Avoiding potential reinfection of the site may also be down to admin ccount security and keeping plugins and WordPress itself up-to-date.

    I urge you to thoroughly read our documentation and free learning center to become well-versed with the plugin and interpreting the data and settings you are curious about:

    https://www.wordfence.com/help/
    https://www.wordfence.com/learn/

    Thanks,
    Peter.

    • This reply was modified 11 months, 3 weeks ago by wfpeter. Reason: Removed copied text from customer to address questions
    Thread Starter kristinubute

    (@kristinubute)

    Thank you I will read with those links you provided.

    Thanks

    Plugin Support wfpeter

    (@wfpeter)

    Thanks! Best of luck with your use of Wordfence going forward, glad to have you on-board.

    Peter.

    Thread Starter kristinubute

    (@kristinubute)

    THanks Peter. If I could just ask a few more questions. I am reading your links also. I appreciate that.

    I won’t be reading all the Live View like you suggested. But still few questions firstly.

    I see in Live View you can actually see when someone has been to Cart or Checkout page (but obviously cannot see who unless they login).

    If someone Used an invalid username ‘admin oR other name that doesn’t exist’ to try to sign in would they be auto blocked permanently OR only a certain time period?

    What does this type of IP range mean? 2607:f298:6:a077::481:f71c

    2405:4800:5f23:6700:ffff:ffff:ffff:fffc

    That doesn’t look like a normal IP (its in our blocked IP area). Not sure whether I did it weeks ago or auto blocked by your software. Is there a way of telling what this IP range means or who it is? It doesn’t look like a normal IP address range.

    We are based in AUstralia. And if an IP range is blocked – Clifton, New Jersey, United States was blocked for UA/Hostname/Referrer/IP Range not allowed – and they are trying to access the login page, and as it says its Clifton New Jersey and NOT Australia, therefore I would assume dodgy and to keep them blocked? I assume the system blocked it ?

    And it says beside that 15 block counts. So someone with that IP has tried 15 times to login? Is that what that would mean please?

    Apologies for my questions in advance.

    Thanks

    Thread Starter kristinubute

    (@kristinubute)

    Also in the scan, it says there is a particular user with a very easy password. Can I send a reset email or something to that User for them to make it a more secure and harder password?

    As in Send a LINK to reset their password ? Or what is the best way to do this please?

    We are NOT using FA2 yet.

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘LIVE VIEW questions’ is closed to new replies.