Forum Replies Created

Viewing 15 replies - 1 through 15 (of 99 total)
  • Thread Starter fleurette

    (@fleurette)

    Hello again,

    I am so very thankful for your reply. Yes, that may well be, I never thought that it would affect Wordfence. Nevertheless, I think the scans still happened as Wordfence made me aware or risk issues with outdated plugins.

    I contacted my host provider who found that a file indeed had been uploaded, and they said they now took care of the situation. It seems my site may really have been compromised, sadly. But they said they took care of it all.

    I do thank you so much again for your kind support and assistance, I am really grateful.

    Thank you again for everything!
    Fleurette

    Thread Starter fleurette

    (@fleurette)

    Hello again,

    can I please ask you, if there is an attempt such as the one from Poland to my “.ftpconfig” and the code answer is 200, does it mean they actually got through?
    My host uses FTP, I am with Hostgator. I contacted them yesterday, they said a file had been uploaded but thought it had been done by me.How do I know?

    The reasons staged for blocking are for example:: Quito, Ecuador was blocked by firewall for a Malicious File Upload in file: files=J89GP.php
    Type: Blocked
    or
    Irkutsk, Russia was blocked by firewall for Malicious File Upload (PHP) at http://mywebsite.com/wp-content/plugins/dzs-portfolio/upload.php

    Is there reason to believe that the ftconfig attempt was successful? I am very concerned now.
    Thank you very much, Fleurette

    Thread Starter fleurette

    (@fleurette)

    Hello again,

    thank you so very much. It is strange I do have a green hook next to it yet it shows the red alert again:
    wp_remote_post() test back to this server failed! Response was: 403 Forbidden<br />
    ..and much more.
    I will try to ask my hosting provider about it, thank you so much. Does that mean Wordfence is not able to scan my site at all?

    Thank you so very much for your support, I truly appreciate it.

    kind regards, Fleurette

    Thread Starter fleurette

    (@fleurette)

    Hello again,

    now I sincerely apologize for the delayed response. In regards to your question if these ips are accessing specific URLs, the reason why I am worried is because it tried to access my website: https//my website name/.ftpconfig.
    It is the ftpconfig I was so worried about. It was Poland and I had others from Russia as well. Is there reason to be worried or should I ignore these? I noticed that most attempts have the 403 or 503 reply code, but some countries get through with the 200 code.

    I did enable the Rate limiting rules. Would you have any specific advice how to set them to protect my site even better?

    I am so very thankful for your response and all your assistance.

    kind regards, Fleurette

    Thread Starter fleurette

    (@fleurette)

    Hello again,

    I checked diagnostics in Wordfence and saw a red alert regarding connecting to Wordfence servers. There is a long error message in “connecting back to this site”.
    How do I fix this, and what is the issue?
    This is what it says at the beginning of the message:
    test back to this server failed! Response was: 403 Forbidden<br />

    I also would like to inquire, what means the response code 200?
    Thank you very much!
    Fleurette

    Thread Starter fleurette

    (@fleurette)

    Hello again,
    thank you very much! I truly appreciate it.

    with kind regards,
    Fleurette

    Thread Starter fleurette

    (@fleurette)

    Hello again,

    when I first started my website you recommended Firebug to me, and it was wonderfully helpful. I now have Firefox Quantum, and unfortunately it is no longer compatible. Would you by chance have a recommendation?

    Thank you very kindly again for your wonderful assistance!
    Fleurette

    Thread Starter fleurette

    (@fleurette)

    Hello,

    I would like to ask one more thing regarding the attacks on my website. Recently I noticed in Wordfence that almost daily I am receiving malicious file upload attacks from bots all over the world. I did not notice these before, and still feel alarmed. Is that a recent change in Wordfence, or is there anything I should do? I am concerned about these attacks. Wordfence scan showed no more alerts, but it still shows ongoing attacks like these: Vietnam Hanoi, Vietnam was blocked by firewall for Malicious File Upload (PHP)
    Can you please help me?
    Thank you very much,
    Fleurette

    Thread Starter fleurette

    (@fleurette)

    Hello again,

    thank you, I am doing backups regularly and now removed the plugins Wordfence pointed out to me. I could not see anything unusual uploaded in wp-content, so I hope, as Wordfence blocked the attacks that everything is fine. I saw in live-traffic that these attacks keep happening from countries all over the world.

    I am still unsure about a setting in Wordfence: How should we treat google crawlers – what option is best to use? I read the article about it but still am not sure whether to set it to verified Goolge crawlers have unlimited access or treat Google like any crawler. Would you be able to advise me?

    Also, I had – if anyone’s request exceeds…set to 60 per minute, your article mentions 240, what is best to do?

    The rule – how long is an IP blocked when it breaks a rule, what is the best setting for it? I often block IPps from Russia permanently as I noticed they keep coming back if I don’t. Is it advisable to set this to a longer time, ie 10 days?

    Does the web firewall be optimized without premium?

    Thank you very kindly for your assistance!
    kind regards, Fleurette

    Thread Starter fleurette

    (@fleurette)

    Hello again,

    Thank you for your reply. I am afraid, I am not a website developer and don’t have the technical knowledge to recognize if there are malicious file, I would be afraid of doing something wrong. I have never done anything like this before, and don’t feel comfortable deleting directories. What could I do?
    I am replacing the unsafe plugins with up to date ones and deleting the old plugins.
    Thank you for your kind assistance in this matter!

    Thread Starter fleurette

    (@fleurette)

    Thank you very much! I had some alerts from September, but since then not anymore. As Wordfence regularly scans my site, if it does not report new issues, then everything is safe again?
    Thank you again!

    Thread Starter fleurette

    (@fleurette)

    I still have the Akismet in my site. I never used it as I am not blogging, it came with the Sugar & Spice theme. I have it disabled since the beginning. I see that it still is being updated, not sure if I should remove or leave it?? If it came with the theme, what is best to do?

    Thank you so much for the advice with the Custom CSS and your earlier recommendation for a replacement, I am so very grateful!

    Thank you again!

    Thread Starter fleurette

    (@fleurette)

    Hello again,
    thank you, I am glad to know. I just have one more question: are disabled plugins a vulnerability risk?
    I still kept the custom css plugin as I want to be sure the new plugin is functioning in the same way, as well as one more plugin that is no longer with WordPress. I left them disabled until I find proper replacement. Is that a risk?

    Thank you again for your kind support!
    Fleurette

    Thread Starter fleurette

    (@fleurette)

    Hello,
    I am very concern about a find in Wordfence.I have a long list of attacks saying malicious file upload php, for example: wp-content/plugins/codecanyon-157782-video-gallery-wordpress-plugin-w-youtube-vimeo-/upload.php blocked by firewall for Malicious File Upload (PHP). Luckily they have been blocked but there are17 of these attacks in one day, and it frightens me to see it. Is there danger of me being hacked? If I am asking a question on I here I shouldn’t I apologize but had so kindly recommended Wordfence to me. It seems all these attacks go to wp-content, here is another example: wp-content/plugins/contus-hd-flv-player/uploadVideo.php, or wp-content/plugins/Tevolution/tmplconnector/monetize/templatic-custom_fields/single-upload.php. I don’t even have these on my site, I don’t understand at all and don’t know what to do!
    I would be so very grateful for advice!
    Thank you, Fleurette

    Thread Starter fleurette

    (@fleurette)

    Hello again,

    Thank you very much, I truly appreciate it!
    kind regards, Fleurette

Viewing 15 replies - 1 through 15 (of 99 total)