WordPress.org

China 简体中文

  • 主题
  • 插件
  • 新闻
    • 文档
    • 论坛
  • 关于
  • 获取 WordPress
获取 WordPress
WordPress.org

Plugin Directory

Protection Against DDoS

  • 提交插件
  • 我的收藏
  • 登录
  • 提交插件
  • 我的收藏
  • 登录

该插件尚未通过WordPress的最新3个主要版本进行测试。 当与较新版本的WordPress一起使用时,可能不再受到维护或支持,并且可能会存在兼容性问题。

Protection Against DDoS

作者:WPChef
下载
  • 详情
  • 评价
  • 开发进展
支持

描述

This plugin resolves performance issues caused by brute force attacks described in the WordPress Codex here: https://codex.wordpress.org/Brute_Force_Attacks

From WordPress Codex:

Due to the nature of these attacks, you may find your server’s memory goes through the roof, causing performance problems. This is because the number of http requests (that is the number of times someone visits your site) is so high that servers run out of memory.

A common attack point on WordPress is to hammer the wp-login.php file over and over until they get in or the server dies. You can do some things to protect yourself.

Protection Against DDoS plugin addresses these issues very well.

It also allows to deny access to common WordPress features that get frequently attacked, like xmlrpc or RSS feeds pages.

CloudFlare users can allow or deny access for visitors from specified countries.

All checks are done via the .htaccess file so that bogus requests can’t even reach your WordPress site and get bounced at the web server level. You can also specify exactly where they can be bounced to.

Compatibility

  • Doesn’t have any known conflicts with any other security plugins.
  • Fully compatible with WordPress multisites.

Advanced users can get more technical information on the FAQ page.

屏幕截图

  • Settings page.

常见问题

How does the plugin work?

The plugin starts working right after you install it. It utilizes a very simple idea: when a real user accesses the login page, the plugin sets a validation cookie for this user. After the user submitted the log in form, the plugin checks if the cookie is there and correct. If so, the user is allowed to log in. Otherwise the user gets bounced off. Since malicious bots attack the WordPress login page directly, they don’t get the protection cookie and hence always get bounced off. Moreover validation happens at the server level BEFORE WordPress is even accessed (via .htaccess file) and hence no load is directed to the WordPress at all. The secure cookie is encrypted and unique for every site so the bots can’t falsify it. Simple and effective!

Can it protect against any DDoS attack?

This plugin protects against DDoS CAUSED by brute-force attacks ONLY. This is the most common cause for an operational WordPress site to be down though. If your site is under attack for other reasons (for example if you got a lot of traffic to one of your posts) this plugin will not help!

What are the system requirements?

This plugin only works on the servers that support .htaccess files. Most Linux servers do.

评价

This is absolutely the best DDoS Protection plugin available

Eli 2020 年 4 月 24 日
Our site was being attacked heavily using exactly the technics for which this plugin was creating for. I cannot thank the creator enough for providing it to the public free of charge. Thank you so much for your contribution. My only concern is that it hasn’t been updated for quite sometime, I really hope it’s not abandoned. I’m surprised this product doesn’t have more reviews and more downloads, I guess it hasn’t had enough promotion. Thank you so much @WPChef, please keep it alive!

This Plugin Saved Me

kcwebguy 2019 年 9 月 9 日 1 回复
I was having a major DDOS against a number of my websites… the attack was taking down my entire VPS and affecting my entire business. I deployed this plugin to all of my sites and saw immediate relief from the attack. I took a screenshot of my load graph with an arrow at the point in time I deployed this plugin. My thanks to this author for a clever and effective plugin.

Serious(ly) Lightweight Extra Security

Gahapati 2017 年 5 月 4 日
When I first came across Protection Against DDoS, I was impressed by the simplicity of the idea and the effectiveness of its execution. Assuming that DDoS attacks will hardly be carried out by lone hackers armed with web browsers, it’s reasonably safe also to assume that accepting and returning cookies will be among the least of their concerns. In which case the attack is stopped dead in its track very early on, in fact before WordPress is even asked to start up its engine. When I first tested this plugin, unfortunately it was not compatible with WP Multisite, yet. But within days of pointing this out to the developer, Protection Against DDoS was updated accordingly! The plugin has earned a permanent resident status in my toolbox!

Works very well

2by2host 2016 年 9 月 3 日
We use this when a WordPress site gets bombarded with bogus traffic and see the results within minutes. We can see how HTTP requests drop right after the plugin is installed. This plugin should be a must for any site.
阅读所有5条评价

贡献者及开发者

「Protection Against DDoS」是开源软件。 以下人员对此插件做出了贡献。

贡献者
  • WPChef

帮助将「Protection Against DDoS」翻译成简体中文。

对开发感兴趣吗?

您可以浏览代码,查看SVN仓库,或通过RSS订阅开发日志。

更新日志

1.5.2

  • Added access control for autodiscover/autodiscover.xml and wpad.dat.

1.5.1

  • Can deny access to xmlrpc, RSS and certain countries now.

1.4.1

  • Multisite compatibility implemented.

1.3

  • Validation cookie is set via JavaScript now and encrypted.

1.2

  • Redirect POST-requests only for login page.

1.1

  • Set validation cookie for all GET-requests.
  • Use random cookie name for better security.

1.0

  • Initial release.

额外信息

  • 版本 1.5.2
  • 最后更新:6 年前
  • 活跃安装数量 3,000+
  • WordPress 版本 3.5.2 或更高版本
  • 已测试的最高版本为 5.4.18
  • 语言
    English (US)
  • 标签
    Brute ForceddosloginPeformancesecurity
  • 高级视图

评级

5 星(最高 5 星)。
  • 4 5-star reviews 5 星 4
  • 0 4-star reviews 4 星 0
  • 0 3-star reviews 3 星 0
  • 0 2-star reviews 2 星 0
  • 0 1-star reviews 1 星 0

添加我的评价

查看全部评论

贡献者

  • WPChef

支持

有话要说吗?是否需要帮助?

查看支持论坛

  • 关于
  • 新闻
  • 主机
  • 隐私
  • 陈列窗
  • 主题
  • 插件
  • 区块样板
  • 学习
  • 支持
  • 开发者
  • WordPress.tv ↗︎
  • 参与
  • 活动
  • 捐赠 ↗
  • 未来五分计划
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

China 简体中文

  • 关注我们的 X(原 Twitter)账号
  • 访问我们的 Bluesky 账号
  • 关注我们的 Mastodon 账号
  • 访问我们的 Threads 账号
  • 访问我们的 Facebook 公共主页
  • 关注我们的 Instagram 账号
  • 关注我们的 LinkedIn 主页
  • 访问我们的 TikTok 账号
  • 访问我们的 YouTube 频道
  • 访问我们的 Tumblr 账号
代码如诗