ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Unsolved A Small Orange - bandwidth limit exceded

    IT Discussion
    12
    71
    3.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Mike DavisM
      Mike Davis
      last edited by

      @scottalanmiller said in A Small Orange - bandwidth limit exceded:

      Also check out the listed threats. That'll help.

      This?
      0_1493165367384_CloudflareThreats.png

      scottalanmillerS 1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller @Mike Davis
        last edited by

        @Mike-Davis Yeah, but I guess that isn't telling us much here.

        1 Reply Last reply Reply Quote 0
        • IRJI
          IRJ
          last edited by

          Are you still getting constant hits on the admin page?

          Mike DavisM 1 Reply Last reply Reply Quote 0
          • StrongBadS
            StrongBad
            last edited by

            I think renaming that admin portal would be smart. A simple way to protect against that part of the traffic. And it will make it easier to find what else might be a target once that is moved.

            1 Reply Last reply Reply Quote 0
            • Mike DavisM
              Mike Davis @IRJ
              last edited by

              @IRJ said in A Small Orange - bandwidth limit exceded:

              Are you still getting constant hits on the admin page?

              I renamed the admin page with the plug in. I'm still getting hammered, but I don't understand how. The bandwidth hasn't gone down since I went to CloudFlare or renamed the admin page. What should I look at next?

              0_1493348420782_aSmallOrange.png

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                Does CloudFlare show the bandwidth the same? Maybe because you exposed your IP it is being hit directly for some reason?

                1 Reply Last reply Reply Quote 0
                • Mike DavisM
                  Mike Davis
                  last edited by

                  yes, CloudFlare shows the bandwidth the same:
                  0_1493378538797_CloudFlareBandwidth.png

                  1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    I wonder why the cache is getting so little.

                    1 Reply Last reply Reply Quote 0
                    • Mike DavisM
                      Mike Davis
                      last edited by

                      Maybe I should put ads on the page. That seems to drive people away... Seriously, Total Unique Visitors Last 24 Hours: 2,763 If it was an attack, it would seem to be distributed.

                      1 Reply Last reply Reply Quote 1
                      • scottalanmillerS
                        scottalanmiller
                        last edited by

                        Maybe there is some bizarre SEO on your page leading people there? Maybe the IP address was used for something else before?

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller
                          last edited by

                          Fire up Google Analytics and look for traffic source info.

                          1 Reply Last reply Reply Quote 0
                          • Mike DavisM
                            Mike Davis
                            last edited by Mike Davis

                            Giving my next question it's own thread:
                            https://mangolassi.it/topic/13548/add-google-analytics-to-wordpress
                            (add Google Analytics to Wordpress?)

                            1 Reply Last reply Reply Quote 1
                            • Mike DavisM
                              Mike Davis
                              last edited by

                              I added Google Analytics. I can see when I hit the page, it says 1 active session. Otherwise it's sitting at 0 active sessions. -Which is what I expect for this seldom used site. However, Cloudflare and A Small Orange insist I'm getting 200+ unique visitors an hour. Where do I go next?

                              1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller
                                last edited by

                                That suggests it isn't picking up the JavaScript. It's a bot of some sort.

                                1 Reply Last reply Reply Quote 0
                                • DanpD
                                  Danp
                                  last edited by

                                  Have you looked into WordFence?

                                  Mike DavisM 1 Reply Last reply Reply Quote 2
                                  • NashBrydgesN
                                    NashBrydges
                                    last edited by

                                    If they are bots, Wordfence has an option to automatically block "fake Google crawlers" found under Wordfence -> Firewall -> Rate Limiting. Wordfence is free for many of it's features but also offers some premium features for paid option.

                                    Something else to watch for is, I noticed that Google crawlers were going ape$hit for a while crawling a couple sites I manage to the tune of hundreds of pages per day. That's since calmed down though. Right around the time I submitted a sitemap to Google Search Console.

                                    Mike DavisM 1 Reply Last reply Reply Quote 0
                                    • Mike DavisM
                                      Mike Davis @Danp
                                      last edited by

                                      @Danp said in A Small Orange - bandwidth limit exceded:

                                      Have you looked into WordFence?

                                      Thanks for the tip. WordFence was the first thing to let me see what's going on. The live view feature let me see the requests and where they are coming from. Mostly it's IPs from all over the world that are trying to pull up admin and register pages that don't exist.

                                      I let it run for a few hours and it didn't put a dent in the traffic, so I just tweaked some of the settings so that it will start blocking after 20 failed attempts for different things. We'll see how it looks tomorrow.

                                      1 Reply Last reply Reply Quote 0
                                      • Mike DavisM
                                        Mike Davis @NashBrydges
                                        last edited by

                                        @NashBrydges said in A Small Orange - bandwidth limit exceded:

                                        If they are bots, Wordfence has an option to automatically block "fake Google crawlers" found under Wordfence -> Firewall -> Rate Limiting. Wordfence is free for many of it's features but also offers some premium features for paid option.

                                        They are bots. When I adjust the filter to "humans" it shows no hits. I turned on the "fake google crawler" rule. We'll see what it looks like tomorrow.

                                        1 Reply Last reply Reply Quote 0
                                        • Mike DavisM
                                          Mike Davis
                                          last edited by

                                          After 2 minutes I've had to turn off "Alert when an IP address is blocked".

                                          1 Reply Last reply Reply Quote 2
                                          • Mike DavisM
                                            Mike Davis
                                            last edited by

                                            Those changes didn't make a dent in the traffic. I set WordFence to block bots after 1 404 error. We'll see what that does.

                                            1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 3 / 4
                                            • First post
                                              Last post