I logged in to the Magazine today because I would like to start in an article. Jetpack's Security Audit is a widget from jetpack that we have enabled, which shows you the latest security logs in the administrator's dashboard, and I saw that there are 287 failed logins (and counting) to the username 'admin'
Is there a way to implement a captcha plugin at the login page? Is there anything else we could do? I have removed all privileges of 'admin' for now (since it's an account that non of us use), and btw I promoted mattdm from editor to admin.
Zacharias (mitzie)
Hi Mitzie,
I am looking for a few plugins that we can push to the staging instance and test.
I will reply with what I find.
Thanks,
- Chris Roberts
----- Original Message ----- From: "Zacharias Mitzelos" zacharias.mitzelos@gmail.com To: marketing@lists.fedoraproject.org Sent: Tuesday, July 15, 2014 11:30:24 AM Subject: Fedora Magazine - Failed login attempts
I logged in to the Magazine today because I would like to start in an article. Jetpack's Security Audit is a widget from jetpack that we have enabled, which shows you the latest security logs in the administrator's dashboard, and I saw that there are 287 failed logins (and counting) to the username 'admin'
Is there a way to implement a captcha plugin at the login page? Is there anything else we could do? I have removed all privileges of 'admin' for now (since it's an account that non of us use), and btw I promoted mattdm from editor to admin.
Zacharias (mitzie)
On 07/16/2014 10:52 AM, Chris Roberts wrote:
Hi Mitzie,
I am looking for a few plugins that we can push to the staging instance and test.
Do we have the Bad Behavior plugin installed? I think that would help with this. It would also help mitigate spam as well. I use Bad Behavior + Akismet on my personal blogs and they do a lot to keep spam at bay, and I don't see a bunch of failed login attempts either. (Granted, my sites are less popular than Fedora Magazine... )
I will reply with what I find.
Thanks,
- Chris Roberts
----- Original Message ----- From: "Zacharias Mitzelos" zacharias.mitzelos@gmail.com To: marketing@lists.fedoraproject.org Sent: Tuesday, July 15, 2014 11:30:24 AM Subject: Fedora Magazine - Failed login attempts
I logged in to the Magazine today because I would like to start in an article. Jetpack's Security Audit is a widget from jetpack that we have enabled, which shows you the latest security logs in the administrator's dashboard, and I saw that there are 287 failed logins (and counting) to the username 'admin'
Is there a way to implement a captcha plugin at the login page? Is there anything else we could do? I have removed all privileges of 'admin' for now (since it's an account that non of us use), and btw I promoted mattdm from editor to admin.
Zacharias (mitzie)
< Do we have the Bad Behavior plugin installed? I think that would help < with this. It would also help mitigate spam as well. I use Bad Behavior < + Akismet on my personal blogs and they do a lot to keep spam at bay, < and I don't see a bunch of failed login attempts either. (Granted, my < sites are less popular than Fedora Magazine... )
Joe,
I will install this on the staging instance see if this causes any issues.
As always we have the staging instance for that purpose so if you feel a plugin is worth trying out please load it up, if it breaks the staging instance its 1 click to bring it back to life
- Chris Roberts
On 07/16/2014 03:05 PM, Chris Roberts wrote:
< Do we have the Bad Behavior plugin installed? I think that would help < with this. It would also help mitigate spam as well. I use Bad Behavior < + Akismet on my personal blogs and they do a lot to keep spam at bay, < and I don't see a bunch of failed login attempts either. (Granted, my < sites are less popular than Fedora Magazine... )
Joe,
I will install this on the staging instance see if this causes any issues.
As always we have the staging instance for that purpose so if you feel a plugin is worth trying out please load it up, if it breaks the staging instance its 1 click to bring it back to life
Groovy, thanks!
Best,
jzb
Hi All,
I have the Bad Behaviour plugin setup on the sgt.fedoramagazine.org instance.
Doing the normal process if it does not crash anything or degrage performance then we will move to staging.
Thanks,
Chris Roberts
----- Original Message ----- From: "Chris Roberts" chris.roberts@croberts.org To: jzb@redhat.com, "Fedora Marketing team" marketing@lists.fedoraproject.org Sent: Wednesday, July 16, 2014 3:05:25 PM Subject: Re: Fedora Magazine - Failed login attempts
< Do we have the Bad Behavior plugin installed? I think that would help < with this. It would also help mitigate spam as well. I use Bad Behavior < + Akismet on my personal blogs and they do a lot to keep spam at bay, < and I don't see a bunch of failed login attempts either. (Granted, my < sites are less popular than Fedora Magazine... )
Joe,
I will install this on the staging instance see if this causes any issues.
As always we have the staging instance for that purpose so if you feel a plugin is worth trying out please load it up, if it breaks the staging instance its 1 click to bring it back to life
- Chris Roberts
marketing@lists.fedoraproject.org