• Resolved jgold723

    (@jgold723)


    This is a follow up to my earlier post regarding a hacking. Upon an attempt to login to my WordPress site, I was presented with a Wordfence screen indicating that I was locked out and that I could receive an email with instructions for getting in.

    The text of that email is below. It contained several links which are explained. I’ve removed identifying material.

    Is this a real, legit Wordfence email?

    =======================================

    Either you or someone else at IP address xx.xx.xx.xx requested instructions to regain access to the website xxxxxxxxxxxx.

    Request was generated at: Friday 21st of December 2018 at 12:48:42 PM

    If you did not request these instructions then you can safely ignore them.
    These instructions will be valid for 30 minutes from the time they were sent.

    Click here to unlock your ability to sign-in and to access to the site. Do this if you simply need to regain access because you were accidentally locked out. If you received an “Insecure Password” message before getting locked out, you may also need to reset your password. Learn More

    Click here to unblock all IP addresses. Do this if you still can’t regain access using the link above. It causes everyone who is blocked or locked out to be able to access your site again.

    Click here to unlock all IP addresses and disable the Wordfence Firewall and Wordfence login security for all users. Do this if you keep getting locked out or blocked and can’t access your site. You can re-enable login security and the firewall once you sign-in to the site by visiting the Wordfence Firewall menu, clicking and then turning on the firewall and login security options. If you use country blocking, you will also need to choose which countries to block.

Viewing 3 replies - 1 through 3 (of 3 total)
  • Hi @jgold723,

    That does look like an email Wordfence would generate when you request an unlock email.

    I would double check to see if the links within the email actually direct you to your website however.

    Other than that, clicking on the various links should regain access to your site.

    Dave

    Thread Starter jgold723

    (@jgold723)

    Thanks Dave.

    The links did direct me to my website with some kind of code that did indeed bypass the wordfence lockout. URL is below:

    https://xxxxxxxx.com/?_wfsf=unlockAccess&key=xxxxxxxxxxxxxxxxxxxxxx&func=disableRules

    Question though – now that I’m back in, do I need to re-enable Wordfence in any way? I checked and it seemed to still be operational, but maybe there’s a switch I’m missing

    • This reply was modified 6 years, 3 months ago by jgold723.

    Yes, there are a few things that need to re-enabled:

    1. Re-enable the firewall (Wordfence -> Firewall) https://i.imgur.com/NUv7qT6.png

    2. Re-enable brute force protection (Wordfence -> All Options) https://i.imgur.com/FWNhdMh.png

    3. Re-block IPs that you have blocked in the past (Wordfence -> Blocking), because the entire IP block list will be cleared

    Dave

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Wordfence lockout email’ is closed to new replies.