Frustrating restrictions in Wordfence when it comes to blocking options
-
I appreciate that there’s the option to block visitors trying to access certain files. And Wordfence provides this instruction in the “Immediately block IPs that access these URLs”:
All URLs must start with a “/” without quotes and must be relative
That starting with a “/” is the problem because there’s an easy way around it – bots scanning for vulnerabilities try accessing via the IP instead. So for example instead of trying https://mysite.com/pma/ they try for https://123.123.123.123/pma/
They also try for
https://123.123.123.123/phpmyadmin/
https://123.123.123.123/mysql/
etc.Bad guys probing for vulnerabilities come from multiple IPs, so I can’t ban by IP. I need the ability to block these bots the moment they try for a URL like the above examples… but there is no such option in Wordfence.
While I’ve got /pma/ and /mysql/ type blocks in “Immediately block IPs that access these URLs”, those don’t work against bots trying the same folders via the IP (as in the examples above).
Is this feature going to be added and/or is there an alternate way to deal with these probes and block the IP of whoever tries to access these files/folders?
- The topic ‘Frustrating restrictions in Wordfence when it comes to blocking options’ is closed to new replies.