Webmaster Forum

Go Back   Webmaster Forum > Web Development > Blogging Forum

Blogging Forum Discuss general blogging issues here - design, integration, posting, trackbacks, ETC. Also discuss blogs you like.


Reply
 
Thread Tools Display Modes
Share |
  #1  
Old 08-29-2007, 03:29 AM
mvandemar mvandemar is offline
Contributing Member
 
Join Date: 07-27-07
Posts: 173
iTrader: 0 / 0%
New WordPress security plugin (need some quick feedback please)

Ok, just wrote a plugin to increase security in WordPress, and could use some quick feedback on it please before I link the download page live from the rest of my site.

It's called Login LockDown:

http://www.bad-neighborhood.com/login-lockdown.html

Basically what it does is it restricts the number of failed login attempts from a given IP block within a short period of time. The default settings cause it to lock out a whole class C after 3 logins fail within 5 minutes. The number of retries, etc, can all be changed from the admin panel. The purpose is to cut down on automated dictionary or brute force hacks.

All feedback is appreciated, thanks.

-Michael
 
Reply With Quote

Advertisement

Advertisement

  #2  
Old 08-29-2007, 03:32 AM
Cricket's Avatar
Cricket Cricket is offline
No Longer Active
 
Join Date: 10-13-03
Location: Texas
Posts: 42,181
iTrader: 0 / 0%
Moving this to the blogging forum.
 
Reply With Quote
  #3  
Old 08-30-2007, 03:47 PM
Jeffro2pt0's Avatar
Jeffro2pt0 Jeffro2pt0 is offline
Senior Member
 
Join Date: 08-03-07
Location: Ohio
Posts: 170
iTrader: 0 / 0%
Hmm, is this really a need worth pursuing? Has this really become a problem?
 
Reply With Quote
  #4  
Old 08-30-2007, 07:29 PM
lucia's Avatar
lucia lucia is offline
Contributing Member
 
Join Date: 03-30-07
Posts: 131
iTrader: 0 / 0%
I think it's a great plugin. My knitting blog was defaced back in 2005-- as were many other blogs at the time. Graywolf's blog was defaced in january. Supposedly Shoemoney's blog was defaced last week.

These defacements are generally done by people who hack in by guessing usernames and passwords in the login pane.

I blogged about your plugin, and my only suggestion is -- if you have time-- to code in something to send an email to the admin when the lockout engages. That way, when there are hackin attempts they can do something like block that IP in htaccess. (Assuming the know how to do this.)

Great plugin!
 
Reply With Quote
  #5  
Old 08-30-2007, 10:51 PM
nks's Avatar
nks nks is offline
Contributing Member
 
Join Date: 03-23-07
Location: Singapore
Posts: 859
iTrader: 0 / 0%
It sounds like a great plugin to me... and I do agree with lucia that large blogging site tends to be victims of hackers.
 
Reply With Quote
  #6  
Old 09-13-2007, 11:32 AM
mvandemar mvandemar is offline
Contributing Member
 
Join Date: 07-27-07
Posts: 173
iTrader: 0 / 0%
Quote:
Originally Posted by lucia View Post
I blogged about your plugin, and my only suggestion is -- if you have time-- to code in something to send an email to the admin when the lockout engages. That way, when there are hackin attempts they can do something like block that IP in htaccess. (Assuming the know how to do this.)

Great plugin!
lucia, I meant to thank you before... so, thank you.

I do plan on adding some functionality, including the ability to run reports and flush the logs, or perma-block someone by IP if it becomes necessary. I will do the email thing too.

Also, just so you know, if anyone had any problems with MySQL errors after installing, the plugin needs to be in it's own directory when you activate it or the necessary tables won't be created. I mentioned this in step #1, but apparently some people missed it, so I emphasized it on the download page.

-Michael
 
Reply With Quote
Go Back   Webmaster Forum > Web Development > Blogging Forum

Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Yahoo Answers Wordpress Plugin madcribz Blogging Forum 8 04-02-2009 01:25 AM
Wordpress Link Directory Plugin!! alect Blogging Forum 11 06-07-2008 05:40 AM
WordPress Plugin Suggestion kiviniar Blogging Forum 0 05-02-2007 10:28 AM
New wordpress plugin learnzed Blogging Forum 2 11-22-2006 10:41 PM


V7N Network
Get exposure! V7N I Love Photography V7N SEO Blog V7N Directory


All times are GMT -7. The time now is 09:32 PM.
Powered by vBulletin
Copyright 2000-2014 Jelsoft Enterprises Limited.
Copyright © 2003 - 2018 VIX-WomensForum LLC