Title: white list hack
Last modified: August 31, 2016

---

# white list hack

 *  Resolved [webentwicklerin](https://wordpress.org/support/users/gbyat/)
 * (@gbyat)
 * [10 years, 4 months ago](https://wordpress.org/support/topic/white-list-hack/)
 * Got a bruteforce attack today from Russia (not with love) after someone/thing
   added “RU” to my whitelist of country codes. using newest version of the plugin.
 * [https://wordpress.org/plugins/ip-geo-block/](https://wordpress.org/plugins/ip-geo-block/)

Viewing 4 replies - 1 through 4 (of 4 total)

 *  Plugin Author [tokkonopapa](https://wordpress.org/support/users/tokkonopapa/)
 * (@tokkonopapa)
 * [10 years, 4 months ago](https://wordpress.org/support/topic/white-list-hack/#post-6990081)
 * Hi gbyat,
 * I think there are many possibilities. Could you send me an email to tokkonopapa
   at yahoo.com? I should know about the deail.
 * Thanks.
 *  Thread Starter [webentwicklerin](https://wordpress.org/support/users/gbyat/)
 * (@gbyat)
 * [10 years, 4 months ago](https://wordpress.org/support/topic/white-list-hack/#post-6990147)
 * sorry for my late answer. there were several issues today, so I found no time
   to have a look at the thread earlier. possibly 2.2.2.1 fixed the problem?
 *  Plugin Author [tokkonopapa](https://wordpress.org/support/users/tokkonopapa/)
 * (@tokkonopapa)
 * [10 years, 4 months ago](https://wordpress.org/support/topic/white-list-hack/#post-6990148)
 * Unfortunately no. But according to your report, I set up a hypothesis and I did
   my best what can do now.
 * We should identify the cause and the details should not be on the public. It’s
   a general principle. That’s why I beg you to contact on email. I ask for your
   kind understanding and cooperation.
 * Thanks.
 *  Plugin Author [tokkonopapa](https://wordpress.org/support/users/tokkonopapa/)
 * (@tokkonopapa)
 * [10 years, 4 months ago](https://wordpress.org/support/topic/white-list-hack/#post-6990205)
 * Dear gbyat,
 * I really thank you for reporting the details about your issue. Your report is
   very helpful to identify the cause.
 * I found it was caused not by hack but my fault of software design. I will try
   to explain.
 * The initial value of “Maching rule” is “Disable”. And when you activate this 
   plugin for the first time, geolocation databased will be downloaded and then 
   the country code will be set according to “your” IP address.
 * This process will be done in background and will take the time for ten seconds
   or so. And actually, this process can also be done by not “you” but “someone”
   in case of race condition.
 * For example, when you activate this plugin but at the same time the attacker 
   carries out brute force attacks, this issue will be caused.
 * This is obviously the bug. I should restrict the authority to do this process.
 * I must apologize to you for involving this issue. And I also really appreciate
   your cooperation to help me finding the cause.
 * I think onece you can fix your country code, you can keep using this plugin. 
   And I will release the fixed version in near future. I also will take care of
   the thread you opend.
 * Thank again!

Viewing 4 replies - 1 through 4 (of 4 total)

The topic ‘white list hack’ is closed to new replies.

 * ![](https://ps.w.org/ip-geo-block/assets/icon-128x128.png?rev=1148568)
 * [IP Geo Block](https://wordpress.org/plugins/ip-geo-block/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/ip-geo-block/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/ip-geo-block/)
 * [Active Topics](https://wordpress.org/support/plugin/ip-geo-block/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/ip-geo-block/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/ip-geo-block/reviews/)

 * 4 replies
 * 2 participants
 * Last reply from: [tokkonopapa](https://wordpress.org/support/users/tokkonopapa/)
 * Last activity: [10 years, 4 months ago](https://wordpress.org/support/topic/white-list-hack/#post-6990205)
 * Status: resolved