• Hello.

    I get a fairly high amount of the https://mywebsite.com/wp-login.php attempts per day so I’m wondering if there is a way to block those. The majority of the attempted logins is the same source I’m sure because the country changes for each one but it is always the same browser, so they seem to be using IPs from other countries to do the login attempts. There are only two other countries that attempt logins but they make far fewer attempts (maybe 5 a day) and they rotate to different IP once I block them but they stay within their country.

    Sorry for the long intro but now the question regarding a feature in the OPTIONS menu in WF. It states:

    ‘Immediately block the IP of users who try to sign in as these usernames’ a box to the left is the area where you can enter the usernames. Below that box where the usernams would be entered it says ‘(One per line. Existing users won’t be blocked.)’

    I’ve often looked at it but was afraid of putting anything other than admin in there (as I don’t use admin as a login) so I’m confident I can’t lock myself out. However the attackers constantly use my wp login name (not sure how they found that out but I’m guessing it was likely in the first year when I started my site (2016) my foolish and ignorant self had a pretty much open site to the world with lots of security holes displayed to the world and no security plugin such as the awesome WF to protect it.

    What I’m wondering is the part where is says “existing users won’t be blocked”, does that mean I can put into the box the user name that I currently use and I still won’t be locked out?

    NOTE: I just checked the FAILED login tab and for some reason there are no failed logins listed other than the two I had recently…how can that be when they are making so many login attempts daily?

    Also if I could ask another quick one, I was once locked out by entering the wrong PW twice (i had caps lock on and didn’t realize it) and I panicked like crazy with beeds of sweat starting to form on my forehead and heart pounding as I couldn’t figure out what to do lol..i can laugh now but it was dreadful feeling that time). Luckily I had set the duration lockout time to a fairly short period so I was able to try again and was able to get in back to my site after a short time passed but during that time it made me realize I don’t get any emails from WF even though I put the corrct email address in where it asks for it. I’ve NEVER rec’d an email from WF, any idea why?

    • This topic was modified 7 years, 4 months ago by skygazer.
    • This topic was modified 7 years, 4 months ago by skygazer.
    • This topic was modified 7 years, 4 months ago by skygazer.
Viewing 7 replies - 1 through 7 (of 7 total)
  • Two things that help with learning and testing how Wordfence behaves. If you have a static IP, simply place your IP number in the “Bypass Rules” dialog on options page. Along with that (or if you don’t have static IP), use a VPN so you can pretend you’re an attacker with no consequence. Not taking these basic measures results in beads of sweat forming on forehead. MTN

    Thread Starter skygazer

    (@skygazer)

    mountainguy2 thank you, that was very useful advice, although I still would like to know what this means:

    ‘Immediately block the IP of users who try to sign in as these usernames’ a box to the left is the area where you can enter the usernames. Below that box where the usernames would be entered it says ‘(One per line. Existing users won’t be blocked.)’

    I would love to know if that means exactly.

    But again thank you for the tip, it is very useful indeed.

    Hi @skygazer
    It means that the plugin won’t block that username you add in the text area if it was found in your list of users on your website, let’s say you added “admin” to the text area and there was a username registered as “admin” on your website, then it won’t be blocked.

    Thanks.

    Thread Starter skygazer

    (@skygazer)

    Hi wfalaa, appreciate the reply.

    1) Ok so if I understand it correctly, it will only block names that don’t exist at all. IF a name exist in my WP it will never block it even if I put the name in that box?

    2) Anyone (even if from a different IP than the users IP) with the correct password can login even if that name is in the box?

    Sorry, I don’t mean to make it complicated but I just want to be really clear so I never lock myself out. I know how to get around it if my IP gets blocked during testing but I know if I get blocked due to user name then I would probably be royally screwed.

    1- Yes.
    2- Yes, if this user you added in the text area exists on your site, anyone with the correct password can log in your site.

    If for any reason you locked yourself out from your site, I’m sure you will find this guide very helpful.

    Thanks.

    Thread Starter skygazer

    (@skygazer)

    wfalaa, I don’t use FTP and don’t have access to an ftp program and frankly don’t have a lot of experience using it. I used to use IPswitch free one from years ago when I used to have a non WP HTML website I had made on my own, I used to use that FTP program but it is no longer free.

    I had already read that FAQ you linked but that’s why I’m still afraid of locking myself out as I don’t have or use FTP.

    I guess that means I could probably do it via my Ubuntu command window? Assuming you say yes then my other problem would be I don’t know too much on how to manipulate files via the command line (I’m using self managed and anything I do I google it and follow the steps to accomplish it on the command line. I suppose if I really had to I would probably eventually figure it out but I would rather not get to that point and deal with that stress…wish there was an easier way.

    • This reply was modified 7 years, 4 months ago by skygazer.

    I understand your point clearly, hopefully you won’t have to do that, but I added the guide just in case it happened, you can use FileZilla as your FTP client, however please read this article about how to use FTP securely.

    Thanks.

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘Q about a specific WF Blocking Feature’ is closed to new replies.