Something not right with Limit Login Attempts
-
Using version 6.9.0 on a WordPress Multisite.
Have been using the plugin for some time now and have been considering buying the pro version for some of the extra features (especially the media folders).
I use the Limit Logins feature and have just spent several days now trying to work out why there was a reload script on the login page for 1 of 3 domains in the multisite.
Long story short I found it was the limit logins causing the problem.
So exactly what happened was as follows:
User entered wrong (autosaved) password several times and got locked out.
The login page now constantly reloads, which triggered a modsecruity and firewall block on our hosting.
My first thoguht days ago was this feature but after disabling it, and because the IP was blocked at the hosting, it didnt fix it, so naturally I didnt think it was limit logins feature.
After allot of back and forth with hosting and several days and allot less hair now, I finally got our hosting to stop blocking temporarily and worked out it was the limit Logins feature.
In saying this, number one, it is very, very bad idea to just block the login page by just continuously refreshing. Maybe redirect to google or something, not just reload the page over and over triggering other systems down the line.
Second, how on earth do we unblock an IP???? When a mistake has happened we need a way to easily unblock the IP.
- The topic ‘Something not right with Limit Login Attempts’ is closed to new replies.