Spam login attempts, ip:s blocked but still “recorded”?
-
Hi,
We noticed a lot of spam login attempts appearing in the Simple History -log.
So we asked our webhost (WP Engine) to set up a nginx rule that block certain ip:s and foreign countries.
However even though these ip:s are now blocked by WP Engine they still keep appearing inside the Simple History log and what I also find strange is that they are using correct usernames.I asked WP Engine about this and they responded:
“I confirmed through our logs that we are not seeing those IPs show in your access logs and that we receive a block when running a curl from those IPs.
So this tells us that those IPs are indeed being blocked and aren’t reaching your server. As to why you’re seeing so many more entries from the Simple History plugin, that seems likely to be an issue with that plugin. It’s likely getting logs from another location, or it could be set to have more robust logging and is recording the blocked attempts. But we have confirmed that the block is working as intended on our end.”Does it make sense? Will Simple History “record” attempts even if they are blocked by nginx rule ?
Thanks!
- The topic ‘Spam login attempts, ip:s blocked but still “recorded”?’ is closed to new replies.