Rev3rseSecurity / wordpress-modsecurity-ruleset

ModSecurity Rule Set for WordPress (WPRS)
102 stars 23 forks source link

Add wprs_check_bruteforce on phase 2,3 / Add Login Failed logging rule #2

Closed theMiddleBlue closed 6 years ago

theMiddleBlue commented 6 years ago

This PR fixes the checking of wprs_check_bruteforce variable (in order to enable or disable the brute-force mitigation function) by adding it on phase:2 and phase:3, and add a new "event logging rule" in order to intercept all Login Failed on wp-login.php.