Home Forums WordPress Plugins Hide My WP False alerts?

This topic is: not resolved
Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #5518

    Hi,

    I get plenty of alerts when my webmaster working on the website.
    (Its not the final website, just temporary, under construction)
    Alerts usually look like this:

    IP: 84.0.14.229
    User ID:
    Date: 2015-10-29T07:43:12+00:00
    Total Impact: 77
    Affected tags: sqli id lfi xss csrf rfe
    
    Affected parameters: REQUEST.mp_bad68c33cc21a989508912b5e70db1c5_mixpanel=%7B%26quot%3Bdistinct_id%26quot%3B%3A+%26quot%3B14c7ec05d7c219-00a196daf-454a0a28-13c680-14c7ec05d7d1c2%26quot%3B%2C%26quot%3B%24initial_referrer%26quot%3B%3A+%26quot%3Bhttp%3A%2F%2Fvitalitasklub.vakondweb.hu%2Fwp-admin%2Fupdate.php%3Faction%3Dupload-plugin%26quot%3B%2C%26quot%3B%24initial_referring_domain%26quot%3B%3A+%26quot%3Bvitalitasklub.vakondweb.hu%26quot%3B%7D, REQUEST.X-Frame-Events_78e0b5f4c65ed19b91a42f153979effd=%7B%26quot%3Bevent%26quot%3B%3A%26quot%3Bnew_gallery%26quot%3B%2C%26quot%3Bgallery_id%26quot%3B%3A2%2C%26quot%3Bgallery_title%26quot%3B%3A%26quot%3Bfogaleria%26quot%3B%2C%26quot%3Bcontext%26quot%3B%3A%26quot%3Battach_to_post%26quot%3B%7D, REQUEST.X-Frame-Events_6d2e9bbd82d259fb2dc136152631a891=%7B%26quot%3Bevent%26quot%3B%3A%26quot%3Bimages_added%26quot%3B%2C%26quot%3Bgallery_id%26quot%3B%3A2%2C%26quot%3Bcontext%26quot%3B%3A%26quot%3Battach_to_post%26quot%3B%7D,
    
    Request URI: /
    Origin: 178.238.222.29
    

    Is it false alert, or what happens?

    #5519
    Suman M.
    Post count: 12480

    These seem to be malicious requests (possible hack attempts). Such request could be either from 3rd party bots or from unsecurely written plugin installed within your site. But you need not worry as HMWP IDS will take care of this and will block such malicious requests if Impact level is more than 20 (default value specified in HMWP IDS).

    You can stop receiving emails regarding this by setting “Notification Threshold” option to 0 in IDS Firewall tab.

Viewing 2 posts - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.