beardedginger
Forum Replies Created
-
Hi,
I am sorry to hear you are experiencing this! Can you please remove the first half of the IP’s that are in the ban list and check to see if that resolves the issue?
This was caused because the file gets cut off and the only fix currently is to limit the number of IP’s in the ban list. We are in the process of finding a new system for this, unfortunately, I do not have a timeline of when that change will be implemented.
- This reply was modified 5 years ago by Jan Dembowski.
Hi,
I am sorry to hear you are experiencing this! Can you please remove the first half of the IP’s that are in the ban list and check to see if that resolves the issue?
This was caused because the file gets cut off and the only fix currently is to limit the number of IP’s in the ban list. We are in the process of finding a new system for this, unfortunately, I do not have a timeline of when that change will be implemented.
Thanks,
Matt
iThemes.comHi,
I am sorry to hear you are running into this. Unfortunately, the Hide Backend feature is known to cause conflicts. This is the only report I have seen of this behavior so it is most likely going to be something specific to your environment.
https://ithemes.com/the-top-5-wordpress-security-myths-debunked/
You may also try checking for a plugin conflict. Deactivate all other plugins and see if that helps. If it does help, then reactivate the plugins one at a time to find the culprit(s), if any.
Can you also check for a theme conflict by switching to a default WordPress theme?
https://ithemeshelp.zendesk.com/hc/en-us/articles/115003073433-Checking-for-a-Conflict
Thanks,
Matt
iThemes.comHi,
I am sorry to hear you are running into this! Will you please try disabling the following features to see if it helps?
Hackrepair Blacklist Feature
(Security> Settings> Banned Users)Filter Long URL Strings
(Security> Settings> System Tweaks)Filter Suspicious Query Strings in the URL
(Security> Settings> System Tweaks)Filter Non-English Characters
(Security> Settings> System Tweaks)You may also try enabling XML-RPC and allowing Full Access to the REST API.
(Security> Settings> WordPress Tweaks> XML-RPC)Thanks,
Matt
iThemes.comHi,
You can manually disable Security via FTP by renaming its directory to something like ithemes-security-pro.bak and that will allow you to get back into your WordPress Dashboard.
The code in the link you provided should have disabled all Security modules. Try the method above to see if you can get back in. Once you are able to, I would advise disabling the Hide Backend module as it does not provide any additional security.
https://ithemes.com/the-top-5-wordpress-security-myths-debunked/
Thanks,
Matt
iThemes.comHi,
Unfortunately, reCAPTCHA does not apply to the Product Review portion of WooCommerce. You may try activating the Only allow reviews from the “verified owners” section. It can be found on the WooCommerce Products settings page.
You can also install the Akismet Anti-Spam plugin to help combat unwanted comments.
Thanks,
Matt
iThemes.comHi,
You will need internet access for the Malware Scan to work. Security utilizes Sucuri’s Site Scan to check pages for malware. You may reach out to Sucuri to find out the specifications of the malware scanner.
Thanks!
Matt
iThemes.comHi,
There are two current Whitelist locations for Security. The 404 File/Folder White List found in 404 Detection Settings and Lockout White List in the Global Settings. The Whitelist is the only place you will need to have an IP listed to make sure that is it permanent. However, if an IP has been added to the Banned List that needs to be added to the Whitelist, you will need to remove the IP from the Banned list first and then add it to the Whitelist in Global settings if it is not already there.
Thanks,
Matt
iThemes.comThe .htaccess will fill up because of users being added to the banned list on the site. Are the majority of the lockouts/bans due to hitting too many 404s, or due to Brute Force attacks?
If 404’s, I would suggest hiring a trusted web developer to get the 404s corrected to prevent the .htaccess from growing so large. In the meantime, you can disable the 404 detection feature.
The .htaccess file will keep growing based on the number of IPs added to the banned list. If the file becomes too large, you can remove the IPs near the top and allow them to be readded again if attacks continue.
Thanks,
Matt
iThemes.comHi,
We have had reports of 217250 modsecurity comodo rule conflicting with Security. With that being said, if you choose to have Comodo WAF you will most likely see issues with Security conflicts. However, if you choose to use Sucuri’s Firewall it will be compatible with Security and Security Pro.
Thanks,
Matt
iThemes.comHi,
There is no caching feature withing Security. However, I would recommend installing W3 Total Cache. I use it on my site and it seems to work pretty well with no/minimal issues.
Thanks,
Matt
iThemes.com
Hi,
If the changes made are from an update there is no cause for concern.
If the changes made are unexpected, you can compare the changed file to those from a recent backup to see exactly what has changed.
You can exclude files and directories in the File Change Detection settings on the Settings page. The general rule is it’s okay to exclude ones that you know are going to be regularly updating. Backup and cache files are a perfect example of this. Doing so will calm a lot of the extra noise.
If you are receiving a lot of these emails you can disable the File Change Detection Notifications and enable the Security Digest in the Notification Center settings. The Security Digest reduces the number of emails sent so you can receive a summary of lockouts, file change detection scans, and privilege escalations. You can set these notifications to be sent daily or weekly.
Thanks,
Matt
iThemes.comHi Mike,
If you just purchased Security Pro you can fill out a ticket for support at the link below.
https://members.ithemes.com/panel/helpdesk.php
Thanks,
Matt
iThemes.comHi,
Where are you getting the 500 error? Is it the result of a malware scan or are you seeing the error somewhere else?
Thanks,
Matt
iThemes.comHi,
You can find more information on Security Pro from the link below.
While we cannot guarantee that will not cause any changes on your site, that module typically works fine as long as no other login plugins are installed.
Thanks!
Matt
iThemes.com