If this is your first visit, be sure to
check out the FAQ by clicking the
link above. You may have to register
before you can post: click the register link above to proceed. To start viewing messages,
select the forum that you want to visit from the selection below.
I had impression that the captcha system was locally on our hosting server?
I tested with a brute force attack on wordpress and after the upgrade its just loading all the time. In the end it shows error. See attachment.
> I tested with a brute force attack on wordpress and after the upgrade the captcha just loading all the time. In the end it shows error. See attachment.
Hi Morten,
Please update to Imunify 1.1.4-9 recent bugfix release. The issue with captcha shall be fixed now.
I tested again on a domain with WP and did a brute force. Got blocked by CSF/LFD because that has less retries before I got blocked. So I turned off CSF/LFD and in the end I got message:
405: Method Not Allowed
No captcha to remove the greylist at all.
But if I change URL from http://domain.tld/wp-login.php to domain.tld in browser I get the captcha screen.
directive: SecRuleEngine
engine: 1
name: Rules Engine
radio_options:
-
name: Process the rules.
option: On
-
name: Do not process the rules.
option: Off
-
name: Process the rules in verbose mode, but do not execute disruptive actions.
option: DetectionOnly
setting_id: 2
state: DetectionOnly
type: radio
url: https://github.com/SpiderLabs/ModSec...#secruleengine
-
default: Off
description: Disables backend compression while leaving the frontend compression enabled.
directive: SecDisableBackendCompression
> Using: 1.1.4-9.el7
>
> I tested again on a domain with WP and did a brute force. Got blocked by CSF/LFD because that has less retries before I got blocked. So I turned off CSF/LFD and in the end I got message:
> 405: Method Not Allowed
>
> No captcha to remove the greylist at all.
> But if I change URL from domain.tld/wp-login.php to domain.tld in browser I get the captcha screen.
Unfortunately, I cannot reproduce this bug in my test env. Could you please open helpdesk request and upload imunify doctor key from this command -
# imunify360-agent doctor
I will do some more testing, but I used Opera with built in vpn to test this. I will also test Chrome and other browsers as I may think it will work fine in Chrome only...
I tested on a new server where I installed IM360. First I tested with CWAF and CSF/LFD enabled. I got blocked by CSF after around 30 attempts and lost connection to server. Then I disabled CSF/LFD and started brute force on customers WP login page again. After 120 logins I gave up! I notice them in CWAF in WHM, but I cannot find any trace of the IP in IM360 I used Chrome to test with.
> I dont see imunify360 mod security ruleset. Can you enable it in "Home »Security Center »ModSecurity™ Vendors » Manage Vendors"?
> Link to ruleset
Hmmm... So you will be providing mod_security rules?
We use to use CWAF as mod_security rules and in the future use IM360 for firewall so IM360 can block those request that are triggered by CWAF!?
We process personal data about users of our site, through the use of cookies and other technologies, to deliver our services, personalize advertising, and to analyze site activity. We may share certain information about our users with our advertising and analytics partners. For additional details, refer to our Privacy Policy.
By clicking "I AGREE" below, you agree to our Privacy Policy and our personal data processing and cookie practices as described therein. You also acknowledge that this forum may be hosted outside your country and you consent to the collection, storage, and processing of your data in the country where this forum is hosted.
Comment