NinjaFirewall ineffective against trespassers admin console penetration
-
Hi, This happened quite many times so I decided to report it.
I get email notifications that someone has logged in to the admin console. [This is very scary news] Because it should not be anybody else than me, I log in to check the trespasser.
It is always a “not in users list” new registration – many times, the user hasn’t even confirmed the registration to the site by clicking on the activation link that is sent in the email after the user registers to the site.
How can anybody breach the security and reach the “Admin Console” when there is NinjaFirewall?
How can we ensure that only the real admin authority can access the admin console of the site? If anybody can get through, then what is the use of NinjaFirewall? It does send the notification, but suppose we read it late, someone could do the harm before we come to know if it. We use NinjaFirewall to stop such penetration and not only for reporting them.
An explanation and a solution would be greatly appreciated.
Thanks,
VinayP.S. I’m using the latest version 3.2.1 of the free NinjaFirewall (WP Edition).
- The topic ‘NinjaFirewall ineffective against trespassers admin console penetration’ is closed to new replies.