Quantcast
Channel: BulletProof Security Forum » All Posts
Browsing all 12461 articles
Browse latest View live

Reply To: BPS Pro product comparison

Hi, Nin Tec are using Basic Htpasswd protection. http://forum.ait-pro.com/forums/topic/password-protecting-a-page/ They also failed to use the Captcha setting in the BPS Pro Login Protection when...

View Article


Image may be NSFW.
Clik here to view.

Reply To: BPS Pro product comparison

This information is not accurate. The test will also include: NinjaFirewall (WP edition). If you aren’t familiar with it, this is how it works: Attacker => HTTP server => PHP => NinjaFirewall...

View Article


Reply To: HEAD request not disabled

I don’t get it either. I just upgraded to the Pro version and did a clean install, so all htaccess files are the BPS standards. The # Request methods filtered are present in both files, and have not...

View Article

Image may be NSFW.
Clik here to view.

Reply To: HEAD request not disabled

I just made a HEAD Request to your website and got a 200 OK Response so if the # REQUEST METHODS FILTERED .htaccess code is in your root .htaccess file then something is overriding the Request Method...

View Article

Image may be NSFW.
Clik here to view.

Reply To: HEAD request not disabled

I forgot to mention that – I already checked that, but just double-checked again – so straight from the root .htaccess through FTP: # REQUEST METHODS FILTERED # This filter is for blocking junk bots...

View Article


Image may be NSFW.
Clik here to view.

Reply To: HEAD request not disabled

Or maybe your web host is doing something in the Server’s httpd.conf file that is preventing this .htaccess directive from working?  Before going too deep at looking at things on your website you...

View Article

Reply To: HEAD request not disabled

OK – I asked them the question. No doubt it will take some time for them to respond, as soon as they do I will post their reply. Thank you for now.

View Article

Image may be NSFW.
Clik here to view.

Reply To: HEAD request not disabled

Yep, sure.  I have never heard of a Host doing something like this before, but if they were doing something like this then they would be using the AllowOverride directive in the Server’s httpd.conf...

View Article


Image may be NSFW.
Clik here to view.

Reply To: Hotlink Protection Do Not Block Google, Bing or Yahoo

Oops! I had specified my client IP address. Back to the drawing board for me! I’ll retest tomorrow with the server address.       This reply was modified 8 hours, 15 minutes ago by  silas88.

View Article


Image may be NSFW.
Clik here to view.

Reply To: Hotlink Protection Do Not Block Google, Bing or Yahoo

Correction:   You do NOT need to whitelist your Server’s IP address – it is recommended, but not required.  Yes, you are correct that if your URL’s have a trailing backslash and/or you have a...

View Article

Reply To: Hotlink Protection Do Not Block Google, Bing or Yahoo

I just retested it this with my server IP address and it works perfectly. That will teach me to read the instructions more carefully! Thanks.

View Article

Reply To: Hotlink Protection Do Not Block Google, Bing or Yahoo

Your .* is why it is working since I was mistaken about the Server IP address.  I cannot remember why that is needed anymore, but there are cases where the Server’s IP address is needed for the code...

View Article

Reply To: HEAD request not disabled

You were right. It is caused by the hosting provider; they confirmed today that method filtering in the .htaccess file is ignored for their standard hosting accounts. For your information: this...

View Article


Reply To: HEAD request not disabled

Wow I am kind of surprised since this is the first Host I have ever heard of that is doing this, but logically it makes sense for them to do something like this.  My guess it is some kind of Brute...

View Article

Reply To: Valid GoogleBot blocked

Just installed BPS pro and Security Log indicates that Jetpack Monitor  is being blocked.  Can you advise the best way to whitelist this? [403 GET / HEAD Request: 3 June, 2014 - 9:16 am] Event Code:...

View Article


Reply To: Valid GoogleBot blocked

David, first thing is always look at the IP where the bot came from. If you google “Whois 10.168.1.23″ then the first result is this page: http://ip.domaintasks.com/10.168.1.22 you can see that...

View Article

Reply To: Valid GoogleBot blocked

Hi Schneider, thanks for your reply.  Jetpack Monitor reported site down as soon as BPS Pro was installed so I’m sure it’s blocking.  With regard to ip, I assumed 10.168.1.22 was a private ip at my...

View Article


Reply To: Valid GoogleBot blocked

Sounds like you are using this XML-RPC protection Bonus Custom Code in the link below.  You can either whitelist IP addresses or Host names or just not use the Bonus Custom Code.  The choice is up to...

View Article

Reply To: Valid GoogleBot blocked

Hi, not using the XML-RPC protection Bonus Custom Code, hadn’t got around to adding it.   I’m also getting a PHP error when I enable/disable Jetpack Monitor.  Not sure if this separate or related…...

View Article

Image may be NSFW.
Clik here to view.

Reply To: Valid GoogleBot blocked

Oops as Schneider pointed out the problem is that 10.168.1.23 is not a valid Public IP address and that is why the problem is occurring.  My coffee had not kicked in yet.  ;)  A 10. IP address is a...

View Article
Browsing all 12461 articles
Browse latest View live