• Resolved n00b82

    (@n00b82)


    my site has been having brute force attacks and 404 notifications for months. I thought I had the security settings as strict as I could get them, with my IP whitelisted on both AIO and the Smart 404 add-on. But today I was locked out. I disabled AIO and found a new user had been created, and my admin email address changed. I’ve been changing and updating as much as I could, but I’m not sure how it happened in the first place.

    I did not find my IP in the htaccess file.
    When I re-activated AIO I was blocked again. Disabled, I can log in.
    I tried re-installing from WP and not my backup, but was locked out again.

    Can you please help me?

Viewing 9 replies - 1 through 9 (of 9 total)
  • Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi, can you try the following solution. Let me know if this helps you in any way.

    Thank you

    • This reply was modified 7 years, 5 months ago by mbrsolution.
    Thread Starter n00b82

    (@n00b82)

    Thank you. I did that, and still had the same problem when I tried to re-install a fresh version of AIO.

    I also de-activated all plugins, and turned them back on one at a time. I was only blocked when I turned on AIO, even after running the settings re-set plugin. I cleared my cookies and tried logging in from another browser also.

    I ran the AIO settings reset a second time, deleted the new version of AIO security, re-installed from wordpress again, and it seemed to work. But there was an added user I did not authorize, pages were changed, email addresses were changed. Is there a way to figure out how it happened so I can prevent it from happening again? I’m already getting 20 or more 404 errors a day again.

    Thank you again

    Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi, that is very strange what you mentioned in the following comment.

    But there was an added user I did not authorize, pages were changed, email addresses were changed.

    Is your site a membership site?

    Do you have more than one admin user in your site?

    Thread Starter n00b82

    (@n00b82)

    It is not a membership site. I had it set so that new users had to be manually approved. I thought I hid the registration page. I am the only admin for the site.

    Plugin Contributor mbrsolution

    (@mbrsolution)

    What firewall settings have you enabled? Do you have Rename Login Page under Brute Force enabled? Do you have any other security plugin installed in your site?

    Thread Starter n00b82

    (@n00b82)

    Firewall settings by tab:
    Basic Firewall Rules tab – everything is checked, however, I did not have the Completely Block Access To XMLRPC option checked when the problem happened
    Additional Firewall Rules tab – everything is checked
    6G Blacklist Firewall Rules tab – both options checked
    Internet Bots tab – check
    Prevent Hotlinks tab – check
    404 Detection tab – check – still getting 404 errors
    Custom Rules tab – I don’t know how to do that so there’s nothing there

    Rename Login Page – yes I was using that when this happened. I am now using the cookie based option.

    Other security plugins – the only other plugin I had at the time was the AIO Smart 404 plugin that goes with the AIO plugin. I have my IP white listed.

    Thank you

    Plugin Contributor mbrsolution

    (@mbrsolution)

    Hi, did you remove the user who was not authorized?

    In regards to the following comment. Have you now enabled completely block access to XMLRPC?

    Basic Firewall Rules tab – everything is checked, however, I did not have the Completely Block Access To XMLRPC option checked when the problem happened

    In regards to the following comment. Only one feature should be enable, the 6G.

    6G Blacklist Firewall Rules tab – both options checked

    Once the above is carried out, keep monitoring this. Report back if it happens again.

    Regards

    Thread Starter n00b82

    (@n00b82)

    Unauthorized user – yes that was the first thing I did. I also changed from the login URL to the cookie based login, changed all passwords, made sure my IP was the only one whitelisted, and started with a new htaccess because I was not sure if the file had been tampered with.

    XMLRPC – yes, now it is checked.

    6G – thank you, 6G is the only option checked now.

    Thank you for your help!

    Plugin Contributor mbrsolution

    (@mbrsolution)

    Are you still being blocked? Are you still receiving Brute Force attacks?

Viewing 9 replies - 1 through 9 (of 9 total)
  • The topic ‘Blocked from accessing dashboard’ is closed to new replies.