Home Forums WordPress Plugins Hide My WP HMWP IDS Alert – Explanations

This topic is: not resolved
Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #8234

    Hi

    I was wondering if you have some kind of help explaining what the differnet alert emails mean? i get a couple of emails a week from the plugin like theese ones below:

    The following potential attack has been detected by HMWP IDS

    . If it’s you please Exclude that parameter or increase Notify Threshold from IDS settings.
    In most cases you don’t need to do anything. Hide My WP protects you!

    IP: 184.154.229.4
    User ID:
    Date: 2016-02-28T18:46:13+00:00
    Total Impact: 70
    Affected tags: xss csrf id rfe lfi

    Affected parameters: REQUEST.err=echo+%28123454320%2B1%29%3Bexit%28%29%3B, REQUEST.e12345=echo+%28123454320%2B1%29%3Bexit%28%29%3B, REQUEST.123=echo+%28123454320%2B1%29%3Bexit%28%29%3B, REQUEST.auto=echo+%28123454320%2B1%29%3Bexit%28%29%3B, REQUEST.txmy=echo+%28123454320%2B1%29%3Bexit%28%29%3B, POST.err=echo+%28123454320%2B1%29%3Bexit%28%29%3B, POST.e12345=echo+%28123454320%2B1%29%3Bexit%28%29%3B, POST.123=echo+%28123454320%2B1%29%3Bexit%28%29%3B, POST.auto=echo+%28123454320%2B1%29%3Bexit%28%29%3B, POST.txmy=echo+%28123454320%2B1%29%3Bexit%28%29%3B,

    Request URI: /wp-content/uploads/wpfoot.php

    The following potential attack has been detected by HMWP IDS

    . If it’s you please Exclude that parameter or increase Notify Threshold from IDS settings.
    In most cases you don’t need to do anything. Hide My WP protects you!

    IP: 46.161.9.8
    User ID:
    Date: 2016-02-28T17:14:58+00:00
    Total Impact: 50
    Affected tags: dt id lfi

    Affected parameters: REQUEST._mysite_download_skin=..%2F..%2F..%2F..%2F..%2Fwp-config.php, POST._mysite_download_skin=..%2F..%2F..%2F..%2F..%2Fwp-config.php,

    Request URI: /wp-content/themes/infocus2/lib/scripts/dl-skin.php

    #8239
    Suman M.
    Post count: 12480

    Hi, HMWP IDS detects malicious requests coming to your site and notify you about it. But all these requests might not be harmful and you need not worry as HMWP IDS will take care of this and will block the malicious requests if Impact level is more than 20 (default value specified in HMWP IDS). You can stop receiving emails regarding this by setting “Notification Threshold” option to 0 in IDS Firewall tab.

    Note: If in case, valid request is also listed as intrusion then hover over that request name and click on Exclude link to add it to exception list.

Viewing 2 posts - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.