Home › Forums › WordPress Plugins › Hide My WP › HMWP IDS Alert – Explanations
- This topic has 1 reply, 2 voices, and was last updated 9 years, 9 months ago by
Suman M..
-
AuthorPosts
-
March 1, 2016 at 10:16 am #8234
Hi
I was wondering if you have some kind of help explaining what the differnet alert emails mean? i get a couple of emails a week from the plugin like theese ones below:
The following potential attack has been detected by HMWP IDS
. If it’s you please Exclude that parameter or increase Notify Threshold from IDS settings.
In most cases you don’t need to do anything. Hide My WP protects you!IP: 184.154.229.4
User ID:
Date: 2016-02-28T18:46:13+00:00
Total Impact: 70
Affected tags: xss csrf id rfe lfiAffected parameters: REQUEST.err=echo+%28123454320%2B1%29%3Bexit%28%29%3B, REQUEST.e12345=echo+%28123454320%2B1%29%3Bexit%28%29%3B, REQUEST.123=echo+%28123454320%2B1%29%3Bexit%28%29%3B, REQUEST.auto=echo+%28123454320%2B1%29%3Bexit%28%29%3B, REQUEST.txmy=echo+%28123454320%2B1%29%3Bexit%28%29%3B, POST.err=echo+%28123454320%2B1%29%3Bexit%28%29%3B, POST.e12345=echo+%28123454320%2B1%29%3Bexit%28%29%3B, POST.123=echo+%28123454320%2B1%29%3Bexit%28%29%3B, POST.auto=echo+%28123454320%2B1%29%3Bexit%28%29%3B, POST.txmy=echo+%28123454320%2B1%29%3Bexit%28%29%3B,
Request URI: /wp-content/uploads/wpfoot.php
The following potential attack has been detected by HMWP IDS
. If it’s you please Exclude that parameter or increase Notify Threshold from IDS settings.
In most cases you don’t need to do anything. Hide My WP protects you!IP: 46.161.9.8
User ID:
Date: 2016-02-28T17:14:58+00:00
Total Impact: 50
Affected tags: dt id lfiAffected parameters: REQUEST._mysite_download_skin=..%2F..%2F..%2F..%2F..%2Fwp-config.php, POST._mysite_download_skin=..%2F..%2F..%2F..%2F..%2Fwp-config.php,
Request URI: /wp-content/themes/infocus2/lib/scripts/dl-skin.php
March 1, 2016 at 6:12 pm #8239Hi, HMWP IDS detects malicious requests coming to your site and notify you about it. But all these requests might not be harmful and you need not worry as HMWP IDS will take care of this and will block the malicious requests if Impact level is more than 20 (default value specified in HMWP IDS). You can stop receiving emails regarding this by setting “Notification Threshold” option to 0 in IDS Firewall tab.
Note: If in case, valid request is also listed as intrusion then hover over that request name and click on Exclude link to add it to exception list.
-
AuthorPosts
You must be logged in to reply to this topic.

