• Resolved gunf

    (@gunf)


    Hi,
    Rate Limiting not working, I have these settings:
    https://ibb.co/VLfw7Dh

    But none of the locks work (except for those whose IP addresses I manually enter in the block).
    Activity Detail
    Yaroslavl, Russia left https://y-expo.ru/ticket/ and was blocked for Manual block by administrator at https://y-expo.ru/wp-json/contact-form-7/v1/contact-forms/72907/feedback
    16.06.2021 14:43:33 (2 hours 20 mins ago)
    IP: 109.161.35.154 Hostname: 109-161-35-154.pppoe.yaroslavl.ru
    Human/Bot: Human
    Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36

    Live traffic does not show calls like this:

    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:50 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:50 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:50 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:50 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:50 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:50 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:50 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:50 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:50 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:51 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:51 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:51 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:51 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:51 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:17:03:51 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 200 1594 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    

    What am I doing wrong?

    The page I need help with: [log in to see the link]

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @gunf, thanks for your question.

    The requests that you’ve given an example of as POST requests may be handled by your Wordfence > All Options > Brute Force settings instead. Can you confirm if the toggle is set to ON and is set in a way that should be blocking these requests? Feel free to provide another screenshot of these if you like.

    You can read more about Rate Limiting and Brute Force protection at the following links:

    https://www.wordfence.com/help/firewall/rate-limiting/
    https://www.wordfence.com/help/firewall/brute-force/

    Thanks,

    Peter.

    Thread Starter gunf

    (@gunf)

    Hi, PEter,
    Thank you for your response.
    Here is a screenshot from the settings:
    https://ibb.co/4JWMQtR
    DDOS attack goes to form, Contact Form 7 plugin, from different IPs, from each a few post requests per second – like this:
    POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback
    In my humble opinion to block such attempts should not be difficult, tell me what can be changed in the settings?

    Thank you!

    Plugin Support wfpeter

    (@wfpeter)

    Hi @gunf,

    Your Rate Limiting settings may not be hit if the frequency of these POST requests are not in excess of 120 a minute – which they are set to for both human and bot. POST requests on custom forms, rather than your default WordPress login/registration pages are controlled by Rate Limiting. Whilst lowering this number can increase false positives, if you’re fairly sure humans won’t click through your site at the rate of 30 or 60 pages a minute under normal conditions, this can be tightened up a little if you wish.

    In Live Traffic, these attempts should appear if you switch “Traffic logging mode” to ALL TRAFFIC? If they do show in this case, then you have the option to block IPs directly from this screen rather than having to manually discover them in logs and add them yourself.

    Thanks,

    Peter.

    Thread Starter gunf

    (@gunf)

    Hi Peter,
    I had a few hundred throws a minute, that’s about it:

    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:58 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:58 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:58 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:58 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:58 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:58 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:59 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:59 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:59 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:59 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:59 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:59 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:59 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:17:59 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:00 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:01 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y-expo.ru 217.15.129.20 - - [16/Jun/2021:18:18:02 +0300] "POST /wp-json/contact-form-7/v1/contact-forms/72907/feedback HTTP/1.0" 403 199 "https://y-expo.ru/ticket/" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36"
    y

    in live traffic, for some reason these requests were not visible, only in access log.
    Why doesn’t the plugin see it and block it?
    Where else can I change the settings?
    Thank you very Match!

    Plugin Support wfpeter

    (@wfpeter)

    Hi @gunf,

    We’ve had a look into your log information and the size of the response is 199 bytes, which is not our block page, as the response would be larger. It seems your server has additional protection that is stopping these as they come in with a 403 before any front-end pages are loaded – which is also good news as they’re being stopped. This is possibly a firewall setup by your host?

    As an aside, Wordfence does not rate limit wp-json, as there is too great a chance for false-positive blocks if plugins/themes make a lot of calls in the background. However, with the log information you’re seeing something server-side is blocking these requests before they hit any pages that’d be logged by Wordfence.

    If WordPress REST API endpoints are attempted, Wordfence will log these if “ALL TRAFFIC” is enabled, but again they’re not even getting this far in your case.

    Thanks,

    Peter.

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘Rate Limiting not working’ is closed to new replies.