Have I read the related troubleshooter articles above before posting (which pages?)? Yes (AdminTools troubleshooting guide)
Have I searched the tickets before posting? Yes
Have I read the documentation before posting (which pages?)? Yes (WAF section)
Joomla! version: 2.5.7
PHP version: 5.3.15
MySQL version: 5.5.23-55
Host: Hostgator
Admin Tools version: 2.4.1
Description of my issue:
Hi Nicholas,
Over the last few days, I've noticed a number of attacks against my client's sites in which someone will try to log into the admin area using a dozen or more different passwords ALL WITHIN THE SAME SECOND. I assume some software must be involved since obviously a human couldn't do this by themselves... Even though I have "Block after 'x' attacks in 1 hours" set low (5 attacks on one site, 2 or 3 on others) the user isn't blocked until after they've had a chance to do a whole bunch of attacks all at once.
See the attached screen capture. You'll see 18 different admin login attempts, from the same IP address, all at 2012-11-08 12:14:54. THEN they were blocked and I received an email notice re: Automatic IP blocking.
If someone manually tries to log in with the wrong info, the setting works fine and will block them after x attempts. I'm just concerned by the discovery of these automated attacks, on more than one client site, all in the last week or so. Do you know how they are bypassing the WAF auto IP block setting by doing so many attacks all at once?
Cheers,
Chris