Forum Replies Created

Viewing 15 replies - 1 through 15 (of 31 total)
  • Forum: Plugins
    In reply to: [Cyr-To-Lat] CTL+WC
    Thread Starter duber777

    (@duber777)

    Здравствуйте.

    Спасибо за информацию.

    Forum: Plugins
    In reply to: [Cyr-To-Lat] CTL+WC
    Thread Starter duber777

    (@duber777)

    Здравствуйте.

    Запрашиваемая информация ниже:

    ### wp-core ###

    version: 6.9.4
    site_language: ru_RU
    user_language: ru_RU
    timezone: Europe/Moscow
    permalink: /%postname%/
    https_status: true
    multisite: false
    user_registration: 0
    blog_public: 0
    default_comment_status: undefined
    environment_type: production
    user_count: 3
    dotorg_communication: true

    ### wp-paths-sizes ###

    wordpress_path: C:\inetpub\websites\site.ru
    wordpress_size: 50,94 МБ (53417185 bytes)
    uploads_path: C:\inetpub\websites\site.ru/wp-content/uploads
    uploads_size: 697,37 МБ (731242167 bytes)
    themes_path: C:\inetpub\websites\site.ru/wp-content/themes
    themes_size: 21,77 МБ (22825253 bytes)
    plugins_path: C:\inetpub\websites\site.ru/wp-content/plugins
    plugins_size: 69,42 МБ (72791964 bytes)
    fonts_path: C:\inetpub\websites\site.ru/wp-content/uploads/fonts
    fonts_size: directory not found
    database_size: 28,00 МБ (29360128 bytes)
    total_size: 867,50 МБ (909636697 bytes)

    ### wp-active-theme ###

    name: Astra (astra)
    version: 4.13.1
    author: Brainstorm Force
    author_website: https://wpastra.com/about/?utm_source=theme_preview&utm_medium=author_link&utm_campaign=astra_theme
    parent_theme: none
    theme_features: core-block-patterns, astra_hooks, widgets-block-editor, align-wide, automatic-feed-links, title-tag, post-thumbnails, starter-content, html5, post-formats, custom-logo, customize-selective-refresh-widgets, editor-style, responsive-embeds, woocommerce, rank-math-breadcrumbs, amp, wc-product-gallery-zoom, wc-product-gallery-lightbox, wc-product-gallery-slider, widgets, menus
    theme_path: C:\inetpub\websites\site.ru/wp-content/themes/astra
    auto_update: Включено

    ### wp-themes-inactive (1) ###

    Twenty Twenty-Five: version: 1.4, author: Команда WordPress, Автоматические обновления включены

    ### wp-plugins-active (16) ###

    Advanced Database Cleaner: version: 4.1.0, author: SigmaPlugin, Автоматические обновления включены
    All-In-One Security (AIOS): version: 5.4.7, author: TeamUpdraft, DavidAnderson, Автоматические обновления включены
    Booster for WooCommerce: version: 8.0.0, author: Pluggabl LLC, Автоматические обновления включены
    Checkout Field Editor for WooCommerce: version: 2.1.8, author: ThemeHigh, Автоматические обновления включены
    CMP - Coming Soon & Maintenance Plugin: version: 4.1.17, author: NiteoThemes, Автоматические обновления включены
    Custom Login Page Customizer: version: 2.5.4, author: Hardeep Asrani, Автоматические обновления включены
    Cyr-To-Lat: version: 6.7.0, author: Sergey Biryukov, Mikhail Kobzarev, Igor Gergel, Автоматические обновления отключены
    Email Templates: version: 1.5.11, author: WPExperts.io, Автоматические обновления включены
    FileBird Lite: version: 6.5.2, author: Ninja Team, Автоматические обновления включены
    Hide Admin Bar From Non-Admins: version: 1.0.2, author: Contributors, Автоматические обновления включены
    Notification: version: 9.0.10, author: BracketSpace, Автоматические обновления включены
    Plus WebP or AVIF: version: 5.11, author: Katsushi Kawamori, Автоматические обновления включены
    SiteOrigin CSS: version: 1.6.5, author: SiteOrigin, Автоматические обновления включены
    Solid Mail: version: 2.2.3, author: SolidWP, Автоматические обновления включены
    WooCommerce: version: 10.7.0, author: Automattic, Автоматические обновления включены
    WooCommerce Remove All Products: version: 8.1.0, author: Gabriel Reguly, Erik Golinelli, Автоматические обновления включены

    ### wp-plugins-inactive (1) ###

    Cyrlitera – transliteration of links and file names: version: 1.3.2, author: Themeisle, Автоматические обновления включены

    ### wp-media ###

    image_editor: WP_Image_Editor_Imagick
    imagick_module_version: 1809
    imagemagick_version: ImageMagick 7.1.1-46 Q16 x64 8209e84:20250318 https://imagemagick.org
    imagick_version: 3.8.1
    file_uploads: 1
    post_max_size: 32M
    upload_max_filesize: 32M
    max_effective_size: 32 МБ
    max_file_uploads: 20
    imagick_limits:
    imagick::RESOURCETYPE_AREA: 128 ГБ
    imagick::RESOURCETYPE_DISK: 9.2233720368548E+18
    imagick::RESOURCETYPE_FILE: 1536
    imagick::RESOURCETYPE_MAP: 64 ГБ
    imagick::RESOURCETYPE_MEMORY: 32 ГБ
    imagick::RESOURCETYPE_THREAD: 1
    imagick::RESOURCETYPE_TIME: 0
    imagemagick_file_formats: 3FR, 3G2, 3GP, AAI, AI, APNG, ART, ARW, ASHLAR, AVCI, AVI, AVIF, AVS, BAYER, BAYERA, BGR, BGRA, BGRO, BIE, BMP, BMP2, BMP3, BRF, CAL, CALS, CANVAS, CAPTION, CIN, CIP, CLIP, CLIPBOARD, CMYK, CMYKA, CR2, CR3, CRW, CUBE, CUR, CUT, DATA, DCM, DCR, DCRAW, DCX, DDS, DFONT, DJVU, DNG, DPS, DPX, DXT1, DXT5, EMF, EPDF, EPI, EPS, EPS2, EPS3, EPSF, EPSI, EPT, EPT2, EPT3, ERF, EXR, FARBFELD, FAX, FF, FFF, FILE, FITS, FL32, FLIF, FLV, FPX, FRACTAL, FTP, FTS, FTXT, G3, G4, GIF, GIF87, GRADIENT, GRAY, GRAYA, GROUP4, HALD, HDR, HEIC, HEIF, HISTOGRAM, HRZ, HTM, HTML, HTTP, HTTPS, ICB, ICO, ICON, IIQ, INFO, INLINE, IPL, ISOBRL, ISOBRL6, J2C, J2K, JBG, JBIG, JNG, JNX, JP2, JPC, JPE, JPEG, JPG, JPM, JPS, JPT, JSON, JXL, K25, KDC, LABEL, M2V, M4V, MAC, MAP, MASK, MAT, MATTE, MDC, MEF, MIFF, MKV, MNG, MONO, MOS, MOV, MP4, MPC, MPEG, MPG, MPO, MRW, MSL, MSVG, MTV, MVG, NEF, NRW, NULL, ORA, ORF, OTB, OTF, PAL, PALM, PAM, PANGO, PATTERN, PBM, PCD, PCDS, PCL, PCT, PCX, PDB, PDF, PDFA, PEF, PES, PFA, PFB, PFM, PGM, PGX, PHM, PICON, PICT, PIX, PJPEG, PLASMA, PNG, PNG00, PNG24, PNG32, PNG48, PNG64, PNG8, PNM, POCKETMOD, PPM, PS, PS2, PS3, PSB, PSD, PTIF, PWP, QOI, RADIAL-GRADIENT, RAF, RAS, RAW, RGB, RGB565, RGBA, RGBO, RGF, RLA, RLE, RMF, RSVG, RW2, RWL, SCR, SCREENSHOT, SCT, SFW, SGI, SHTML, SIX, SIXEL, SPARSE-COLOR, SR2, SRF, SRW, STEGANO, STI, STRIMG, SUN, SVG, SVGZ, TEXT, TGA, THUMBNAIL, TIFF, TIFF64, TILE, TIM, TM2, TTC, TTF, TXT, UBRL, UBRL6, UIL, UYVY, VDA, VICAR, VID, VIFF, VIPS, VST, WBMP, WEBM, WEBP, WMF, WMV, WPG, X3F, XBM, XC, XCF, XPM, XPS, XV, YAML, YCBCR, YCBCRA, YUV
    image_format_transforms: image/heic → image/jpeg, image/heif → image/jpeg, image/heic-sequence → image/jpeg, image/heif-sequence → image/jpeg
    gd_version: bundled (2.1.0 compatible)
    gd_formats: GIF, JPEG, PNG, WebP, BMP, AVIF, XPM
    ghostscript_version: not available

    ### wp-server ###

    server_architecture: Windows NT 10.0 AMD64
    httpd_software: Microsoft-IIS/10.0
    php_version: 8.5.5 64bit
    php_sapi: cgi-fcgi
    max_input_variables: 1000
    time_limit: 300
    memory_limit: 512M
    max_input_time: 60
    upload_max_filesize: 32M
    php_post_max_size: 32M
    curl_version: 8.19.0 OpenSSL/3.5.5
    suhosin: false
    imagick_availability: true
    pretty_permalinks: true
    htaccess_extra_rules: false
    static_robotstxt_file: false
    current: 2026-05-03T20:02:14+00:00
    utc-time: Sunday, 03-May-26 20:02:14 UTC
    server-time: 2026-05-03T23:02:12+03:00

    ### wp-database ###

    extension: mysqli
    server_version: 8.0.46
    client_version: mysqlnd 8.5.5
    max_allowed_packet: 4194304
    max_connections: 151

    ### wp-constants ###

    WP_HOME: undefined
    WP_SITEURL: undefined
    WP_CONTENT_DIR: C:\inetpub\websites\site.ru/wp-content
    WP_PLUGIN_DIR: C:\inetpub\websites\site.ru/wp-content/plugins
    WP_MEMORY_LIMIT: 40M
    WP_MAX_MEMORY_LIMIT: 512M
    WP_DEBUG: false
    WP_DEBUG_DISPLAY: true
    WP_DEBUG_LOG: false
    SCRIPT_DEBUG: false
    WP_CACHE: false
    CONCATENATE_SCRIPTS: undefined
    COMPRESS_SCRIPTS: undefined
    COMPRESS_CSS: undefined
    WP_ENVIRONMENT_TYPE: undefined
    WP_DEVELOPMENT_MODE: undefined
    DB_CHARSET: utf8mb4
    DB_COLLATE: undefined

    ### wp-filesystem ###

    wordpress: writable
    wp-content: writable
    uploads: writable
    plugins: writable
    themes: writable
    fonts: does not exist
    mu-plugins: writable

    ### solid-mail ###

    active_connections_number: 1
    active_connections_names: other
    brevo_connections: undefined
    mailgun_connections: undefined
    sendgrid_connections: undefined
    ses_connections: undefined
    smtp_connections: 1
    sent_emails: 1
    Артикул,Имя,
    123,"Название товара"

    Проблема проявляется даже при деактивации всех плагинов кроме WC.

    Thread Starter duber777

    (@duber777)

    I understand. I will try to find solutions on my own. Thanks for the feedback.

    Thread Starter duber777

    (@duber777)

    UPD: After a few minutes, it was re-reproduced out of the blue. After a few minutes, it was re-reproduced out of the blue. Diagnostic data: https://dropmefiles.com/RFhpn

    It is not very clear which directory the plugin needs access to. By means of IIS, I have configured access restriction by IP addresses to the wp-admin directory and files wp-login.php, xmlrpc.php outside. The rest of the directories are open for writing.

    Thread Starter duber777

    (@duber777)

    That’s right, I use this version in conjunction with the IIS web server.

    File system-level access to the cache folder is not restricted. These entries appeared in the PHP_errors text file of Windows Server OS. I have now manually deleted the entire cache. Restarted the web server. Watching. I haven’t turned on debugging yet, but the check built into the plugin completes successfully.

    For information: the following plugins are also installed on the site: All In One WP Security, WP SMTP and CMP – Coming Soon & Maintenance Plugin and maintenance mode is enabled – the stub page.

    For the correct operation of your plugin, after all, no more settings (except for permalink) need to be made in WP (version 6.3)?

    Thread Starter duber777

    (@duber777)

    Hello.

    I found the reason. The problem was with the Captcha 4WP plugin.

    Thanks for the help.

    Thread Starter duber777

    (@duber777)

    Hi. Thanks for feedback.
    Keep in touch.

    Thread Starter duber777

    (@duber777)

    UPD: Won.

    After deleting wp-login.php brute force continued.
    After that, I assumed that the attack is using the XML-RPC method.
    In addition to the steps in this article:
    https://www.bluelightdev.com/wordpress-restrict-access
    i also denied access to the xmlrpc.php file.
    After that, for a whole day, not a single attempt to guess passwords.

    Nevertheless, I have a wish to the developers – to add support for IIS web servers to the plugin in terms of access restrictions. Of all the other plugins that I have tried, none of them can interact with IIS.

    Thread Starter duber777

    (@duber777)

    Yes, I meant it.
    I tried to add IP to the white list, but it does not work. I suppose, due to the fact that I have an IIS web server and there is no .htaccess file. Instead, there is a web.config. I also assumed that brute-force goes through XML-RPC, but after disabling it, the attacks continued (checked with XML-RPC validator), for the same reason that this plugin function does not support working with the IIS web server.
    Last idea: IIS blocks access only to the wp-admin address, but access via wp-login.php remains open. Completely deleted this file from the root of the site. After some time, I will return to the place, go to the plugin and look “Failed login reports”.

    Thread Starter duber777

    (@duber777)

    I tried to add IP there, but it did not work, I think, because I do not have a .htaccess file, because web server not Apache.
    The issue was solved by adding a snap-in to block addresses in the IIS console.

    Thread Starter duber777

    (@duber777)

    Hi.
    Enough time has passed and the update has not come out, when to expect?

    Thread Starter duber777

    (@duber777)

    Thanks, I will try if the need arises.

    Thread Starter duber777

    (@duber777)

    Ok, understand.
    It’s just that at an Internet speed of 9Mbit, a delay (1 sec) in opening the authorization page is visually noticeable. By the way, I’m using the My Private Site plugin by David Gewirtz, which forcibly redirects requests to the login page.
    There may be incompatibility with third-party plugins, or is it his normal behavior in such a bundle.

    I think at the moment the ticket can be closed, but if possible, see if it can possibly optimize performance. If I notice something else, I will write in a new topic.

    Thread Starter duber777

    (@duber777)

    Now checked on another plugin “Simple Google reCAPTCHA”, the same error comes out, probably such a feature of the work of such plugins.
    OK. Can you at least try to optimize the speed of work by reducing the number of requests?

    Thread Starter duber777

    (@duber777)

    WPS Hide Login and Hide Login Page from Webcraftic.

Viewing 15 replies - 1 through 15 (of 31 total)