Error: Cookies are blocked or not supported by your browser. You must enable cookies to use WordPress.

Home Forums BulletProof Security Pro Error: Cookies are blocked or not supported by your browser. You must enable cookies to use WordPress.

Viewing 8 posts - 1 through 8 (of 8 total)
  • Author
    Posts
  • #36127
    private_team_A
    Participant

    Hi,

    We are facing some issue with login security lockdown.

    Our website has a sudden issue where correct credentials are not being accepted.

    During first submit, an error is appearing ‘Error: Cookies are blocked or not supported by your browser. You must enable cookies to use WordPress.’

    On re-entering the correct password, it says that the password is incorrect. After 3 times, account is locked.

    We tried many solutions such as disabling all plugins , themes and checking codes which set test cookie etc in wp-login.php and even deleted .htacess from root.  We even downgraded php from version 7.2 to 7.1 , changed browsers etc etc.

    However, the only thing that worked was re-setting the password.

    However, on re-start of my pc, the issue is back and login security is blocking the account after 3 attempts with the RIGHT password.( We unlock using xternal tools)

    The only difference between previous site (now staging) and this one is your plugin and nothing else has changed.

    Hence, we feel somehow your plugin is changing something which is affecting the login process. We do not use any plugin to modify the login.

    Can you please help us out as your plugin places many .htacess files and deleting only the root one is not resolving the issue.

    If the password is right, login should not be locked down?

    We really cannot even imagine re-building the site once more as we lost 3 weeks from planned launch and now costs are adding up as this was not our 1st delay 🙁

    Thanks a lot.

    Best Regards,

    Team A

    #36129
    AITpro Admin
    Keymaster

    See this WordPress StackExchange forum topic for possible causes for this error/problem > https://wordpress.stackexchange.com/questions/166181/cant-log-in-error-cookies-are-blocked-or-not-supported-by-your-browser-you

    Here is another WordPress.org forum link that may be helpful to figure out what is causing the problem > https://wordpress.org/support/topic/cant-login-admin-cookies-problem/

    #36133
    private_team_A
    Participant

    Hi,

    Thank you for the links. But nothing works. I have a strange observation:

    When I copy paste the password it is accepted. When I type the same it is rejected.

    Have you got any clue about this? Is this suspicious behaviour?

    As a last step after everything else is exhausted we will un-install bullet proof security to see if this resolves the issue but we wanted to hear your opinion first.

    We have gone through your forum and we know you seem to have issues with sucuri whose firewall we use.

    Additionally, you plugin changes things very heavily and hence since staging works fine without your plugin, it seems the possible cause can be narrowed down to : Our hosting, PHP 7.2 , sucuri or your plugin.

    We are narrowing down and it would help a lot to hear what you think.

    Thanks a lot.

    Best Regards,

    Team A

    #36134
    AITpro Admin
    Keymaster

    When I copy paste the password it is accepted. When I type the same it is rejected.

    This is very strange. I have never heard of that problem before. Could the problem be caused by a Browser Add-on or extension or something else in your Browser or on your computer? Are you using a Proxy Browser? Post a link to your website’s login page so I can check it with Google Chrome Developer Tools.

    #36135
    private_team_A
    Participant

    Hi,

    We are going to email you the link as we want to be very private in public forums about who we are 🙂

    However, please post your reply here without mentioning us (our site) or anything which can link this post to us directly. This is because unfortunately google is not delivering emails from your domain or your ID. Eg: We never get updates when you reply to this post and hence our delay in reply.

    This is the first time in my life I encountered this issue! Something malicious or something as simple as script error. I confirm, that copy pasting password works but typing wont!

    We tried different browsers but the same result. Copy paste and it works! We will positively try out all combinations until we find the root cause. Things cannot happen without a code 🙂

    Thanks a lot for having a look.

    Best Regards,

    Team A

    #36136
    AITpro Admin
    Keymaster

    Automated emails/email replies are being sent successfully from this forum.  Most likely your web host has anti-spam software installed such as Spam assassin or other similar anti-spam software that blocks/rejects automated emails as spam.  This is a very common problem these days.  40% of all automated emails get rejected/blocked as spam by web host anti-spam software such as Spam assassin and other similar anti-spam software.  Contact your web host and ask them to stop blocking/rejecting automated emails as spam.

    I checked your website login page and something is wrong with JTC CAPTCHA .  When you do not type in any Username or Password and you click the WordPress Log In button you should see this JTC CAPTCHA error message:  ERROR: Incorrect CAPTCHA Entered.  I am not seeing the JTC error message.  When I look at the Source Code of your Login page I see Google Analytics Dashboard for WP js code in your Login page Source Code.  Maybe that js code is breaking the JTC js code?  I will need to login to this website to figure out what is causing the problems.  I will respond directly to the email that you sent to me.

    #36138
    private_team_A
    Participant

    Hi,

    Thanks a lot for confirming. I have emailed you credentials.

    I sent you the email before reading this. Hence, I wrote ‘how to replicate’ which you can ignore. I just mentioned 5 points which I was asked to mention while giving production server access (We had bad past exp lol). Between me and you, please treat it with care and security and let me know what changed afterwards 🙂

    Many thanks and have a great morning 🙂 Your emails went to spam and I had them marked as not spam to help your domain 😉 . I will try and get them white listed manually. Hope this helps you in the future.

    Best Regards,

    Team A

    #36139
    AITpro Admin
    Keymaster

    Status Update:  The Login page problem did not occur for me when I logged into your site with the login info you sent to me.  So based on all the info you sent to me describing the problem, I believe this is some sort of caching problem.  I did find and fix a few nick nack things that needed to be fixed.  Specific details were included in the emails I sent to you.

Viewing 8 posts - 1 through 8 (of 8 total)
  • You must be logged in to reply to this topic.