Depending on the version of OHSecurity that you have installed on your website (Core or Professional) will depend on what settings you are able to configure within OHSecurity's Global Configuration. Below we have listed all of the settings for both Core and Professional and have listed them accordingly.
Email Options (Core and Professional)
There are two settings in which you are able to configure within the Global Configurations Email Options and they are:
- Enable Emails
- Email Address
1: When OHSecurity blocks a request and bans the IP address, an email is sent to the email address which is specified within Global Configuration. By default an email is sent every time that an IP address gets banned - within the drop-down menu you are able to change this setting to any of the following settings:
- Yes - Every time an IP address is banned or if there is an error
- No - Never send an email - even if an error occurs
- Only when an error occurs - Only send emails if there is an error banning the IP address
2: If you would like emails to be sent to an alternative address to the one specified within Global Configuration - enter the email address here. If you don't enter a valid email address, OHSecurity will default to the address specified within Global Configuration.
Allow/Ban 'Bad Bots' (Partial Core and Professional)
Over the years we have identified a number of 'bots/site scrapers' that we feel shouldn't have access to websites. They become a 'bad bot' when they:
- don't declare a website URL
- contain a '@gmail' email address
- crawl a whole website within a couple of minutes (increasing server load which could cause your website to become inaccessible)
- SEO crawlers that competitors set on your website to gather information
- perform bad requests
- don't obey your 'robots.txt' file
- and more...
All bad bots by default are banned if they crawl/visit your website however, you are able to allow specific bots by setting the value to 'Allow' instead of 'Ban'.
With OHSecurity Core - there's a total of 10 'bad bots' while the Professional version includes 140 'bad bots'.
Bad Content settings (Core and Professional)
When hackers compromise a website - it could take months before the web master even finds out about the hack. Many hackers only make the 'bad content' visible to search engines such as Google, Bing and Yahoo so it only effects the listings within search engines. We developed the 'Content Scanner' to alert the web master as soon as bad content has been identified. Some websites such as this one, has published articles that contain some of these 'bad words' so we added a 'Threshold Limit' were the web master can specify a limit within the Global Configuration - making sure that they aren't sent any emails when users visit legitimate articles that contain the specific words.
The web master can set the threshold limit value as follows:
This means that the 'bad words' are able to be displayed on a page but they won't receive any emails until the limit is reached.
Login Attempts (Professional version only)
Because hackers try to 'brute force' the admin area of your website, we 'hijack' the login default login procedure so we are able to prevent brute force attempts. Our plugin increases the security of your website by banning these attempts to prevent a hacker from gaining access to your system. For this plugin you are able to configure the following:
- 'Empty Password Limit'
- 0 - Ban at first attempt
- 'Username not found'
- 0 - Ban at first attempt
- 'Lock Down Time Period'
- 30 minutes
- 1 hour
- 1 hour 30 minutes
- 2 hours
- 4 hours
- 5 hours
- 'Max Failed Login Attempts'
Empty Password Limit - Hackers try multiple username and password combinations in order to breach your system and 'take over' your website. They do this by attempting to login via the administrator area of your website but they aren't really 'smart' about it. When you are setting this value, please bear in mind that if you allow 'real' people to login to your system - you have to be aware that they will sometimes forget to enter a password so please set this limit carefully.
Username not found - As mentioned above hackers try multiple variations of usernames and passwords and this settings 'catches' the hackers when they enter a password but the 'username' doesn't exist within your system.
Max Failed Login Attempts - Along with multiple username and password combinations, they like to 'mix things up' by using multiple IP address - making them think that they 'can't be caught'. They typically perform between 10 and 20 login attempts and then switch to a different IP address and perform the attempts again. Here we set a maximum number of attempts that when triggered OHSecurity will put your system into Lock Down mode for the specified time that you have configured with the 'Lock Down Time Period' setting.
Lock Down Time Period - When the 'Max Failed Login Attempts' limit has been reached - OHSecurity will put your website into 'Lock Down' mode. During Lock Down your system prevents any one from logging in - thus preventing the hacker from trying multiple times. Please note, all aspects of logging in are disabled - you wont be able to login to the administrator area and your users wont be able to login via the front end.
Advanced (Core and Professional)
Test Mode - This allows you to perform requests that would normally get you band - providing that you put OHSecurity into test mode first. Simply select 'Enabled' and click save. Please note, when OHSecurity is in Test Mode - a 'banner' is placed at the top of your website alerting you to the fact that you have enabled 'Test Mode'.
Download ID (Professional version only)
A download ID is only needed for the Professional version of OHSecurity and requires an active subscription of either 'OHSecurity Professional' or 'Deluxe Package'. Subscriptions can be obtained via the Subscribe page.
In order to update OHSecurity Professional from within the extension, you first need to enter your Download ID