• Resolved NiallASD

    (@niallasd)


    They just keep coming without pause, I currently have 90 from the last few minutes and I’ve probably deleted 90 more.

    They’re from different areas around the world too – what is going on?

    The page I need help with: [log in to see the link]

Viewing 14 replies - 1 through 14 (of 14 total)
  • Hi @niallasd

    Thanks for reaching out!

    If you can send over a screenshot from live traffic of these users getting blocked I may be able to explain!

    Thanks,

    Joshua

    Thread Starter NiallASD

    (@niallasd)

    Thanks, here’s a screenshot – looking at my inbox they occurred between 1.11pm and 1.26pm – they strangely stopped after I started this thread.

    https://greencastleparish.com/wp-content/themes/greencastleparish/Untitled-1.png

    Hi @niallasd

    It appears that I do not have access to view that screenshot, would you mind uploading that to another site like imgur?

    Thanks,

    Joshua

    Thread Starter NiallASD

    (@niallasd)

    https://imgur.com/a/JrzS27M

    Sorry, didn’t think

    Hi @niallasd
    Sorry about that, could you resend the screenshot with advanced information?

    This is so I can see the block reason.

    Thanks,

    Joshua

    Thread Starter NiallASD

    (@niallasd)

    I don’t understand.

    Hi @niallasd

    Can you head over to Wordfence -> Live Traffic and enabled “Expand Results”

    This will allow me to see more information on these blocks.
    Thanks,

    Joshua

    Thread Starter NiallASD

    (@niallasd)

    Looking at the full list I see an onslaught of these – I often get emails, but never to the extant of which I did at the time I mentioned above

    https://imgur.com/i0tV8zi

    Hi @niallasd

    Looks like theres nothing to worry about there!

    Could be an anomaly where you got higher than usual traffic or a small attack.

    Looks like Wordfence is working as intended.

    All the best,

    Joshua

    Thread Starter NiallASD

    (@niallasd)

    Thanks, good to get reassurance – would it be a bad idea to turn off email notifications?

    Email alerts are a big part of what a good security plugin, like Wordfence, does. They alert you to a problem that you should address. These alerts are configurable on the?Wordfence Dashboard?>?Global Options?page in the section marked “Email Alert Preferences”. You can set the alerts you want and which ones you don’t want. You can even tell Wordfence the maximum number of emails it can send per hour.? We have a good page for documentation that includes a helpful video here:
    https://www.wordfence.com/help/dashboard/alerts/
    Here are some of the options there that I wanted to mention.

    • Email me if Wordfence is deactivated – This can be helpful if you manage client sites and want to be alerted if they may disable Wordfence without realizing its purpose, or just want to keep a close watch on your own site. I also enable the next option, “Email me if the Wordfence Web Application Firewall is turned off”, for the same reason.
    • Alert me with scan results of this severity level or greater. I set this to High. This lets you get alerts for the really important things like a plugin installed that has a vulnerability and skips ones like alerts for regular theme or plugin update alerts.
    • Alert when someone is blocked from logging in using a password found in a breech. – This is user preference but knowing that breeches like Ashley Madison and Equifax gave hackers a huge list to use as defaults to try in brute force attempts, I’d prefer to not make it easier on them and know so I can make sure my users aren’t using one.
    • Alert me when someone with administrator access signs in – Please note that I also have checked the box to only alert me when it is from a new location. If someone steals my admin credentials (and cell phone since I am using 2FA) and logs in from Poland instead of my home IP address I certainly want to know. Otherwise I’d rather not have the excess emails
    • Alert me when there are a large increase of attacks on my site – I use these as a reminder to go check my latest scan results, my blocking rules, and do a general walk through of my security settings. It never hurts to be prepared and watchful
    • Maximum email alerts to send per hour – I usually set this to 4 because I don’t want so many emails that I start to miss things because of the “noise” they create. With a smaller number I’m more likely to see trends and absorb the information I need.


      These are the alerts I don’t enable because they are informational only. There isn’t anything really actionable because Wordfence has already done its job.
    • Alert when an IP address is blocked
    • Alert when someone is locked out from login
    • Alert when the “lost password” form is used for a valid user

    Hopefully this helps with the alert fatigue. ??
    Mia

    Thread Starter NiallASD

    (@niallasd)

    Thank you Mia

    No problem! Happy to help. ??

    Mia

    Thread Starter NiallASD

    (@niallasd)

    I keep getting user locked out emails again, 55 in the last 10 minutes and they’re still coming, I’m back to worrying about that.

Viewing 14 replies - 1 through 14 (of 14 total)
  • The topic ‘Suddenly getting lots of ‘user locked out from signing in’ emails’ is closed to new replies.