• Resolved cnymike

    (@cnymike)


    In addition to WP Security, I have WordFence setup to alert me when login attempts are made.

    With WP Security, I’ve renamed the login page from wp-admin to something else. So since going to /wp-admin generates a 404 page error, it has basically eliminated admin login attempts to my site.

    However, today I’ve received dozens of locked out login attempts…

    This email was sent from your website “xxxxxxx” by the Wordfence plugin at Tuesday 15th of September 2015 at 08:56:02 AM
    The Wordfence administrative URL for this site is: https://www.xxxxxxx.com/wp-admin/admin.php?page=Wordfence

    A user with IP address 89.35.211.63 has been locked out from the signing in or using the password recovery form for the following reason: Used an invalid username ‘test’ to try to sign in.
    User IP: 89.35.211.63
    User hostname: 89.35.211.63
    User location: Piatra Neam?, Romania

    How is this happening?

    https://www.ads-software.com/plugins/all-in-one-wp-security-and-firewall/

Viewing 15 replies - 1 through 15 (of 23 total)
  • Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi, in some cases having two security plugins might not work well. Depending on the settings you enable in both plugins. If you enable similar settings in both security plugins it can cause a conflict.

    You should really choose one or the other. If you must have both then find out what changed before the problem begun.

    Thread Starter cnymike

    (@cnymike)

    The plugins have been co-existing for months ever since I first installed them. And WordFence doesn’t have an alternative login page as WP Security offers. I don’t really have conflicting settings as far as I can tell.

    Plugin Contributor mbrsolution

    (@mbrsolution)

    I understand but something changed in your website or else this would not have occurred? Did you update any plugins, your theme, did anything changed in your server? Did you update WordPress?

    Thread Starter cnymike

    (@cnymike)

    Yes, all of those things occurred.

    Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi, you have to work out which of the above has caused the problem between both plugins.

    Actually, any conflict in between the two plugins has nothing to with the original question here. I am running this plugin on multiple sites, some without wordfence installed.

    What seems to be happening is somehow the website is still being attacked from multiple ip’s targeting the username “test”.

    This is particularly odd, like op originally posted, the default wp login page has been changed and is no longer, or should no longer be /wp-admin .

    SO the question is, how is the website being attacked at the new url, by trying to brute force with username “test” and what can be done to put a stop to this.

    Thread Starter cnymike

    (@cnymike)

    I am getting a deluge of these attempts. Between three websites being targeted, over 200 attempts a day. This just started about 3 days ago.

    Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi can you check to make sure you have the following enabled Enable Pingback Protection: located under Firewall tab.

    Can you also try and set up the Cookie Based Brute Force Prevention under Brute Force feature.

    i have enabled pingback protection on some of the sites, but Cookie Based Brute Force Login Prevention was setup on almost all of them.

    Plugin Contributor mbrsolution

    (@mbrsolution)

    @pyromania666 can you start a new support thread please.

    Thank you

    Plugin Contributor wpsolutions

    (@wpsolutions)

    Pyromania666,
    Try the following:
    using a browser go to your website URL and add xmlrpc.php
    Eg,
    yoursite.com/xmlrpc.php

    Note: if you have installed wordpress in a subdirectory and not root then you would type:
    yoursite.com/<name of your subdir>/xmlrpc.php

    Tell me what you see when you do the following.

    Thread Starter cnymike

    (@cnymike)

    Well I’ll chime in on this one…

    some of my sites result in: XML-RPC server accepts POST requests only.

    while others report: 403 Permission Denied You do not have permission for this request /xmlrpc.php

    On a site that i know for a fact a few of these Site Lockouts with username “test” i just tried what @wpsolutions said and i get a standard 404 page “You 404’d it. Gnarly, dude.” LOL.

    @wpsolutions, let me know if that helps or if there is anything you wish me to try. I got sites that have only “All In One WP Security” installed and others that have AIOWPS and Wordfence.

    I have turned on pingback requests in the firewall, and i still have to see if those specific site are getting hit still. It must be the same bot, since the username it’s using is “test” but the IP keeps changing.

    Thread Starter cnymike

    (@cnymike)

    I’m getting test and administrator

    Plugin Contributor wpsolutions

    (@wpsolutions)

    Pyromania666,
    If the pingback protection rule is enabled and working properly you are supposed to get a 403 response and not a 404 (Page not found).
    It is likely that you are typing in the wrong URL path to the xmlrpc.php file.

    cnymike,
    For the sites where you are not getting a 403 response, is the pingback protection feature turned on and are those the sites where you are getting lockout notifications?

Viewing 15 replies - 1 through 15 (of 23 total)
  • The topic ‘Locked out login attempts’ is closed to new replies.