Serious Issues with Protection
-
Hi Guys,
I am a developer and a programmer, with a moderate amount of system admin experience with Unix systems. I have a network of several WordPress based websites, and I use WordFence on all of them. As a matter of fact, I recommend the plugin to all of my clients as well, very often actually installing and configuring it for them, quite a few of whom use the paid version on my recommendation.
Yesterday, my knowledgebase received a pretty standard (and pretty large) Distributed Denial of Service(DDoS) attack. After some time of this happening, luckily, my hosting company contacted me to inform of the attack, the IP addresses they had recorded, a log of the (extremely extensive) activity, and some advice for how to proceed. We dealt with the attack without too much of a large problem.
I am wondering, how it is that this was missed by the plugin? As a programmer myself, I certainly understand that there are no guarantees, and that it is impossible for the plugin to capture everything; I also understand and appreciate the quality of the plugin and the amount of time spent maintaining it. Which I appreciate, I absolutely do.
I am however, quite concerned, as it would seem to me, that this was an extremely unsophisticated attack, and so the plugin’s ability to handle, or at the very least recognize, any attacks, specifically DDOS attacks and anything slightly more sophisticated than them is very much in question at the moment. I don’t even expect that the plugin would’ve acted in the handling of the attack – I am simply shocked, frankly, that it went completely unnoticed for many hours, I was quite confident that it would have at the very least alerted me to what was happening, not to mention following all the very strict log-in security options I set myself. The plugin has no idea anything happened at all. This, obviously, is a huge concern for me. So I suppose my question, or questions rather, would be, is this normal, am I protected, is there something I am mis-understanding about the protection and am I not correct in assuming that based on what is advertised that this should of absolutely, at the very least, been noticed and the admin alerted to it? Also, as a side issue, once I received the IP addresses from the hosting company, when I went to add them to the block list, on my main website, the feature absolutely did not work and I now discover there seems to be a bug preventing me from adding any IP’s manually to the block list, the block list which did have several IP’s added as of many months ago, to be permanently blocked – all of which are silently missing now, and this is on an entirely different website, entirely different install. This is quite a lot to be going wrong at once, especially considering this is two separate versions of the plugin.
I most certainly cannot in good faith continue to recommend something to my clients if it is not what I thought it was in terms of quality and protection, nor can I use a product incapable of protecting my network – however, I also, as stated, am a very long time user of the plugin and would like to understand and make sure I am not jumping to conclusions before I stop using and recommending WordFence.
Can one of you maybe help shed some light on why this might have happened, how it slipped through, etc., please?
For obvious reasons, I would like to discuss the details privately if possible, so if you could perhaps provide an email address, or just email me at [ redacted, support is not offered via email, Skype, IM etc. only in the forums ], I would appreciate it.
Thank You,
Nicole
- The topic ‘Serious Issues with Protection’ is closed to new replies.