• Resolved yydevelopment

    (@yydevelopment)


    Hey there, first of all thanks for this great plugin.

    I have one site that getting a lot of lockdown notifications and I have tried to block the login option to only my IP range.

    I went into Brute Force >> Login Whitelist and I have tried to add there my IP

    There were 2 problems i have found. First of all that option doesn’t work because i still have access to the login page when i use different ip.

    The second problem is that i can’t insert IP range. So if for example i enter this IP 33.22.33 it auto complete the full IP and add 33.222.33.44.

    Am i doing something wrong or is it a bug on the plugin?
    Thanks

Viewing 8 replies - 1 through 8 (of 8 total)
  • Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi,

    There were 2 problems i have found. First of all that option doesn’t work because i still have access to the login page when i use different ip.

    What type of server is your site hosted in? Also, can you elaborate further on how you carried out your different IP address test?

    The second problem is that i can’t insert IP range. So if for example i enter this IP 33.22.33 it auto complete the full IP and add 33.222.33.44.

    Here are some examples of IP ranges permitted in our plugin.

    – Example 1: 195.47.89.*
    – Example 2: 195.47.*.*
    – Example 3: 195.*.*.*

    Thank you

    Thread Starter yydevelopment

    (@yydevelopment)

    Hey thanks for your answer.

    For the ip range problem my site is in hebrew (With RTL) so when i looked on the “more info button and the examples the * went to the other side of the page and i missed it but now it’s working when i use *.

    About the server, I am using shared hosting on Fastcomet.
    About how I tested it I have tried to test it with my mobile that have different ip, with a proxy and now i have tired and ask a friend to test it as well.

    In all cases there are still access to the login page.

    Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi, are you running any cache system in your site or server? When you view this feature does it display your current IP address? You could also try a different option in the following IP Retrieval Settings located in WP Security -> Settings -> Advanced Settings.

    Let me know how you go.

    Thank you

    Thread Starter yydevelopment

    (@yydevelopment)

    Hey thanks again,

    I have tried to stop the cache plugin and as far as i now there is no cache from the hosting.

    I have also tried playing with the IP address and it didn’t worked out.

    For now i have traied to add google recaptcha so i will try and give up the blocking IP option and hope that will help.

    Thanks again

    Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi, if you are looking for better security, try one of the Brute Force features like Rename Login Page.

    Kind regards

    Thread Starter yydevelopment

    (@yydevelopment)

    Hey thanks i did that as well but it doesn’t seems to work. Seems like somehow some users/bots are able to find the login page even if i change the url.

    It’s strange i was getting email lockout messages from your plugin and nothing i tried was helping with stopped getting it. Seems like recaptcha don’t fix it as well.

    I even tried to remove the content on wp-login.php so when you go into wp-admin you get no login option and i still get the lockout notifications.

    At the end i gave up and I allow now only one login try, made the password much more complex and remove the logout notification email messages.

    Plugin Contributor mbrsolution

    (@mbrsolution)

    Let me know if your issue is resolved. I am curious to know.

    Thank you

    Thread Starter yydevelopment

    (@yydevelopment)

    Hey, if wasn’t able to fix it with the plugin so if gave up and canceled the option to send me email on lockdown notification.

    Even when i removed the login page i was still getting lockdown notifications from the plugin so i am not 100% sure what the problem anymore.

    You can mark this question as solved, thank you for your help appreciate that.

Viewing 8 replies - 1 through 8 (of 8 total)
  • The topic ‘Login whitelist blocker doesn’t work’ is closed to new replies.