• Resolved pstidsen

    (@pstidsen)


    Hi there,

    Recently I started to receive 20-30 e-mails with the subject “[Wordfence Alert] domain.dk Increased Attack Rate” on a daily basis. I am a bit concerned, what does it mean? Should we do something?

    
    The Wordfence Web Application Firewall has blocked 148 attacks over the last 10 minutes. Below is a sample of these recent attacks:november 26, 2021 8:05am  94.231.103.138 (Denmark)     Blocked for LFI: Local File Inclusion in POST body: 0 = /var/www/domain.dk/public_html/wp-includes/js/jquery/jquery.min.js
    november 26, 2021 8:05am  94.231.103.138 (Denmark)     Blocked for LFI: Local File Inclusion in POST body: 0 = /var/www/domain.dk/public_html/wp-includes/js/jquery/jquery.min.js
    november 26, 2021 8:04am  94.231.103.138 (Denmark)     Blocked for LFI: Local File Inclusion in POST body: 0 = /var/www/domain.dk/public_html/wp-includes/js/jquery/jquery.min.js
    november 26, 2021 8:04am  94.231.103.138 (Denmark)     Blocked for LFI: Local File Inclusion in POST body: 0 = /var/www/domain.dk/public_html/wp-includes/js/jquery/jquery.min.js
    november 26, 2021 8:04am  94.231.103.138 (Denmark)     Blocked for LFI: Local File Inclusion in POST body: 0 = /var/www/domain.dk/public_html/wp-includes/js/jquery/jquery.min.js
    november 26, 2021 8:04am  94.231.103.138 (Denmark)     Blocked for LFI: Local File Inclusion in POST body: 0 = /var/www/domain.dk/public_html/wp-includes/js/jquery/jquery.min.js
    november 26, 2021 8:04am  94.231.103.138 (Denmark)     Blocked for LFI: Local File Inclusion in POST body: 0 = /var/www/domain.dk/public_html/wp-includes/js/jquery/jquery.min.js
    november 26, 2021 8:04am  94.231.103.138 (Denmark)     Blocked for LFI: Local File Inclusion in POST body: 0 = /var/www/domain.dk/public_html/wp-includes/js/jquery/jquery.min.js
    november 26, 2021 8:04am  94.231.103.138 (Denmark)     Blocked for LFI: Local File Inclusion in POST body: 0 = /var/www/domain.dk/public_html/wp-includes/js/jquery/jquery.min.js
    november 26, 2021 8:04am  94.231.103.138 (Denmark)     Blocked for LFI: Local File Inclusion in POST body: 0 = /var/www/domain.dk/public_html/wp-includes/js/jquery/jquery.min.js
    

    The page I need help with: [log in to see the link]

Viewing 4 replies - 1 through 4 (of 4 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @pstidsen, thanks for reaching out to us.

    This blocking appears to be for the WP Rocket plugin’s “Remove Unused CSS” feature.

    You can switch the firewall status to Learning Mode in Wordfence > All Options > Basic Firewall Options for a few days to see if it will hopefully catch all possible combinations of requests. Set a suitable date for it to automatically switch back to Enabled and Protecting.

    Alternatively, if you have a virtual private server or a dedicated server for just this website then you can add the server’s public IP address to the option Allowlisted IP addresses that bypass all rules found in the Wordfence > All Options > Advanced Firewall Options section. Do not do this if your site is hosted on a shared hosting server because if another compromised site on the same server attacks your site then the attacks will bypass all Wordfence protection.

    Thanks,

    Peter.

    Thread Starter pstidsen

    (@pstidsen)

    I will try that. Thanks! ??

    Plugin Support wfpeter

    (@wfpeter)

    No worries @pstidsen, let us know in a new topic if you have further Wordfence questions in future!

    Peter.

    Thread Starter pstidsen

    (@pstidsen)

    It helped, thanks!

Viewing 4 replies - 1 through 4 (of 4 total)
  • The topic ‘Many e-mails: [Wordfence Alert] domain.dk Increased Attack Rate’ is closed to new replies.