• Hi, we are using the Wordfence as our security plugin and we set a number of attempts for user to login until they are blocked. Is there a way to show a message with the number of attempts remaining? Because I can’t see it, only that the username or password is wrong.
    Also where and when the user can see the following message?
    https://freeimage.host/i/J8f6Fdg
    When the user is blocked is redirected only to the following page. I would like to show the message from above instead. To know how they can contact us.
    https://freeimage.host/i/J8fPQNj

    Thank you !

    The page I need help with: [log in to see the link]

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Support wfphil

    (@wfphil)

    Hi

    If we showed how many attempts were left, an attacker could check back periodically to see when the countdown was cleared, which would tell how many tries each IP address gets, and how long it would wait for the countdown to reset. Therefore it would give them them the same benefit as regular visitors of not getting locked out and being able to try again sooner (assuming the lockout period is set longer than the option “Count failures over what time period”), but their benefit is multiplied by how many IP addresses they control.

    The custom block message will be shown on the block page and I see your custom message on the block page screenshot that you provided.

    Thread Starter viktor05

    (@viktor05)

    I understand that, but the attacker can’t do the same if the attempt are not showing, they can count after how many tries they were blocked and to use it as you said on other IP’s?
    Also, other plugins like “Limit Login Attempts Reloaded” are showing the attempts number, how do they protect from these attacks about which you said?
    Regarding block message, I apologize, I don’t know how I missed it in the block page.

Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘Login attempts message’ is closed to new replies.