• Resolved adamkolenda

    (@adamkolenda)


    Hi,

    It looks as “Additional Firewall Rules” applied from your plugin not reflecting within the application.

    The rules which are specifically not working and were flagged as an issue during the PEN test of the application are:

    * Listing of Directory Contents
    * Trace and Track
    * Bad Query Strings
    * Advanced Character String Filter

    All available under Firewall -> Advanced Firewall Rules.

    These are the ones I proved do not apply properly on my Application but started to question the other functionality of the plugin.

    I wonder if this plugin can conflict with others and that is why it is not working properly on my side or there might be some sort of a bug in the software itself?

    Side is behind internal firewall during development phase and therefore cannot be accessed from the internet thus I have not provided the path

    Thanks in advanced.

Viewing 7 replies - 1 through 7 (of 7 total)
  • Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi,

    I wonder if this plugin can conflict with others and that is why it is not working properly on my side or there might be some sort of a bug in the software itself?

    Yes, there are times that different plugins, theme and or server settings can conflict with AIOWPS plugin.

    Thank you.

    Thread Starter adamkolenda

    (@adamkolenda)

    Thanks, but is there any way I can verify whether it is clash with other software or simply a bug within a plugin?

    Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi, yes you can start by carrying out the following steps. First disable all other plugins except AIOWPS. Then carry out a test. If it works then you can assume there is a conflict with one of the plugins you deactivated. If it does not work, then it could be related to your server’s configuration.

    Kind regards.

    Thread Starter adamkolenda

    (@adamkolenda)

    Thanks,

    Tried the first part already and it seems that this did not resulted in any improvement which would suggest the latter. I had an infrastructure engineer looking specifically at the Apache config to see whether there is anything which would interfere with this plugin but they have not called out anything specifically.

    Any idea what on server configuration side could be an issue?

    Thanks

    Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi, who is your host? Can you share some information about your server specs?

    Thank you.

    Thread Starter adamkolenda

    (@adamkolenda)

    Yes sure,

    So solution is hosted internally and this is server spec:

    
    ### wp-core ###
    
    version: 5.8
    site_language: en_US
    user_language: en_US
    permalink: /%postname%/
    https_status: true
    user_registration: 0
    default_comment_status: open
    multisite: false
    user_count: 7
    dotorg_communication: true
    
    ### wp-paths-sizes ###
    
    wordpress_path: /var/www/html
    wordpress_size: 58.63 MB (61482119 bytes)
    uploads_path: /var/www/html/wp-content/uploads
    uploads_size: 55.99 MB (58707671 bytes)
    themes_path: /var/www/html/wp-content/themes
    themes_size: 27.07 MB (28389017 bytes)
    plugins_path: /var/www/html/wp-content/plugins
    plugins_size: 193.88 MB (203295415 bytes)
    database_size: 42.49 MB (44551228 bytes)
    total_size: 378.06 MB (396425450 bytes)
    
    ### wp-active-theme ###
    
    name: Hestia (hestia)
    version: 3.0.17
    author: ThemeIsle
    author_website: https://themeisle.com
    parent_theme: none
    theme_features: core-block-patterns, title-tag, post-thumbnails, automatic-feed-links, custom-logo, html5, custom-header, customize-selective-refresh-widgets, custom-background, themeisle-demo-import, align-wide, header-footer-elementor, starter-content, editor-color-palette, menus, editor-style, widgets
    theme_path: /var/www/html/wp-content/themes/hestia
    
    ### wp-themes-inactive (4) ###
    
    Hestia Pro: version: 3.0.17, author: ThemeIsle
    Twenty Nineteen: version: 2.1, author: the WordPress team
    Twenty Twenty: version: 1.8, author: the WordPress team
    Twenty Twenty-One: version: 1.4, author: the WordPress team
    
    ### wp-mu-plugins (1) ###
    
    Health Check Troubleshooting Mode: author: (undefined), version: 1.7.2
    
    ### wp-plugins-active (37) ###
    
    AlertMe!: version: 2.0.3, author: Bloom WP
    All In One WP Security: version: 4.4.9, author: Tips and Tricks HQ, Peter Petreski, Ruhul, Ivy
    Big File Uploads: version: 2.0.1, author: Infinite Uploads
    Change WordPress Login Logo: version: 1.1.6, author: Boopathi Rajan
    Classic Editor: version: 1.6.2, author: WordPress Contributors
    Code Snippets: version: 2.14.1, author: Code Snippets Pro
    Create And Assign Categories For Pages: version: 1.2, author: Sandeep Singh
    Elementor: version: 3.4.3, author: Elementor.com
    Elementor Pro: version: 3.3.8, author: Elementor.com
    Embed Any Document - Embed PDF, Word, PowerPoint and Excel: version: 2.7.0, author: Awsm Innovations
    Essential Addons for Elementor: version: 4.8.4, author: WPDeveloper
    Essential Addons for Elementor - Pro: version: 4.4.8, author: WPDeveloper
    Filester - File Manager Pro: version: 1.7.3, author: Ninja Team
    Force Login: version: 5.6.2, author: Kevin Vess
    Health Check & Troubleshooting: version: 1.4.5, author: The www.remarpro.com community
    LDAP/Active Directory Login for Intranet Sites: version: 24.0, author: miniOrange
    Media File Renamer: version: 5.2.5, author: Jordy Meow
    Members: version: 3.1.5, author: MemberPress
    Oasis Workflow Pro: version: 8.7, author: Nugget Solutions Inc.
    PDA Access Restriction: version: 1.3.2, author: BWPS
    PDA Download Link Statistics: version: 1.3.5, author: BWPS
    Post SMTP: version: 2.0.23, author: Yehuda Hassine
    Prevent Direct Access: version: 2.7.6, author: BWPS
    Prevent Direct Access Gold: version: 3.3.2, author: BWPS
    Protect Pages & Posts Gold: version: 2.0.2, author: BWPS
    Qubely - Advanced Gutenberg Blocks: version: 1.7.2, author: Themeum.com
    Radius client (Radius login): version: 2.1.3, author: miniOrange
    Real Media Library (Free): version: 4.15.0, author: devowl.io
    Real Physical Media: version: 1.3.31, author: devowl.io
    Timeline Widget Addon For Elementor: version: 1.3, author: Cool Plugins
    Ultimate Addons for Gutenberg: version: 1.24.2, author: Brainstorm Force
    Visibility Logic for Elementor: version: 2.1.7, author: StaxWP
    Visualizer: Tables and Charts for WordPress: version: 3.6.1, author: Themeisle
    Visualizer: Tables and Charts Manager for WordPress AddOn: version: 1.10.2, author: ThemeIsle
    WordPress Importer: version: 0.7, author: wordpressdotorg
    WP Activity Log (Premium): version: 4.3.2, author: WP White Security
    WP Rollback: version: 1.7.1, author: Impress.org
    
    ### wp-plugins-inactive (2) ###
    
    NTLM SSO: version: 1.0, author: miniorange
    WP 2FA - Two-factor authentication for WordPress: version: 1.7.1, author: WP White Security
    
    ### wp-media ###
    
    image_editor: WP_Image_Editor_GD
    imagick_module_version: Not available
    imagemagick_version: Not available
    gd_version: 2.2.5
    ghostscript_version: not available
    
    ### wp-server ###
    
    server_architecture: Linux 4.18.0-305.3.1.el8_4.x86_64 x86_64
    httpd_software: Apache/2.4.37 (Red Hat Enterprise Linux) OpenSSL/1.1.1g
    php_version: 7.4.6 64bit
    php_sapi: fpm-fcgi
    max_input_variables: 1000
    time_limit: 0
    memory_limit: 256M
    max_input_time: 60
    upload_max_size: 100M
    php_post_max_size: 8M
    curl_version: 7.61.1 OpenSSL/1.1.1g
    suhosin: false
    imagick_availability: false
    server-headers: unknown
    htaccess_extra_rules: true
    
    ### wp-database ###
    
    extension: mysqli
    server_version: 8.0.21
    client_version: mysqlnd 7.4.6
    
    ### wp-constants ###
    
    WP_HOME: undefined
    WP_SITEURL: undefined
    WP_CONTENT_DIR: /var/www/html/wp-content
    WP_PLUGIN_DIR: /var/www/html/wp-content/plugins
    WP_MAX_MEMORY_LIMIT: 256M
    WP_DEBUG: false
    WP_DEBUG_DISPLAY: true
    WP_DEBUG_LOG: false
    SCRIPT_DEBUG: false
    WP_CACHE: false
    CONCATENATE_SCRIPTS: undefined
    COMPRESS_SCRIPTS: undefined
    COMPRESS_CSS: undefined
    WP_LOCAL_DEV: undefined
    
    ### wp-filesystem ###
    
    wordpress: writable
    wp-content: writable
    uploads: writable
    plugins: writable
    themes: writable
    mu-plugins: writable
    
    
    Plugin Contributor mbrsolution

    (@mbrsolution)

    Thank you for sharing the information above. It all looks normal to me. I can’t see anything out of the ordinary. However I don’t have this issue in my site and no one else has reported this issue. This might be just be an isolated issue with your server and site configuration. Unfortunately there is not much more I can do to help you. For now, I recommend you don’t activate the features causing a conflict in your site.

    Kind regards.

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘Additional Firewall Rules – Rules applied from plugin but not reflecting on app’ is closed to new replies.