• Hi

    I would like to ask a question concerning the “Hide Backend” option.

    We have iThemes Security installed on our website and the “Hide Backend” option is active and works as intended.

    However, the website has WooCommerce installed. With WooCommerce comes a customer login page. This login page is not hidden and it should not be hidden. But it is possible to login as administrator on the WooCommerce customer login page.

    If the point of hiding the backend is to minimize the risk of brute force attacks against admin accounts, then the WooCommerce customer login page should also be secured in someway. Otherwise what’s the point of hiding the WordPress login page while attackers can still take aim at the WooCommerce customer login page?

    Do you have any suggestions how to prevent the WooCommerce customer login page from accepting the credentials of an administrator, even if it is the correct credentials?

Viewing 6 replies - 1 through 6 (of 6 total)
  • Micha

    (@michapaashuis)

    Follow. I have the same question.

    Yes, same question here. Even in all kind of custom login, the plugin is detecting all of them and apply every single security policy to all forms, IP bans as a example: So imagine that a customer is trying to login in his woocommerce account and get baned (depends on your settings) for 10 minutes or whatever. These policies should be only for login/register wordpress form.

    :S

    Thread Starter Gevorg

    (@gev0rg)

    Is there any reply from the developers concerning this issue?

    Thread Starter Gevorg

    (@gev0rg)

    It has been more than two weeks that I posted this question, but so far no one from the development team has replied.

    It is a security issue that I raised here, a faulty concept if you will.

    If there is an alternative login-page, like the customer login-page from WooCommerce, then all the security measures involving “Hide backend” becomes nil and void. Because it is possible to login as administrator on the customer login-page which is not hidden behind a cryptic login-link.

    Can you please share your opinion regarding this issue? Are you aware of it?

    According to the FAQ :

    = Where can I get help if something goes wrong? =
    * Official support for this plugin is available for iThemes Security Pro customers. Our team of experts is ready to help.

    Free support may be available with the help of the community in the www.remarpro.com support forums (Note: this is community-provided support. iThemes does not monitor the www.remarpro.com support forums).

    That last sentence isn’t entirely true. Occasionally iThemes does respond in this forum. Especially after a plugin update…

    That said the Hide Backend module is considered security by obscurity. It doesn’t really strengthen the security of your site, like strong passwords or two-factor authentication do. Personally I only find it usefull for preventing automated brute force attacks which might slow down the site.
    Just sharing my thoughts.

    To prevent any confusion, I’m not iThemes.

    Thread Starter Gevorg

    (@gev0rg)

    Thank you for your thoughts.

    I do understand the concept which you mention but I think it’s worthwhile to consider the scenario which I describe. It’s like a backdoor that circumvents the core concept of “Hide backend”.

    Is it possible to prevent the login of certain user roles, including admin, on the customer login page of for example WooCommerce, while not messing around with the default WordPress login which has been hidden with iThemes Security?

    What comes to my mind is to use certain keywords in admin- or shop manager user-names and redirect or block login-attempts which try to gain access through the customer login page, using credentials that contain those keywords.

    Would this mess around with the default WordPress login-procedure?

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘Hide backend works, but what about WooCommerce customer login page?’ is closed to new replies.