Have I read the related troubleshooter articles above before posting (which pages?)? Yes
Have I searched the forum before posting? Yes
Have I read the documentation before posting (which pages?)? Yes
Joomla! version: 1.5.24
PHP version: 5.2
MySQL version: 5.0
Host: n/a
Admin Tools version: 2.1.10
Description of my issue:
Hi,
I use the latest version of Admin Tools Pro v2.1.10. I am facing 2 security problems:
1. I have set "Administrator secret URL parameter" parameter in WAF, i.e. only few characters from set a-z, e.g. "asdf". However, I am still able to access Joomla Admin page with url "https://www.mysite.com/administrator", i.e. without providing the parameter "?asdf" at the end of the URL. I didn't make any tests on HTTP, because all HTTP requests are redirected to HTTPS.
2. I have set admin name and password in "Password-protect Administrator". The password is more than 15 characters long and it do contain special characters after the 9th character. I have noticed, that I am able to login by providing only the first 8 characters of the password. I have tried Firefox v6.0.2 , as well as IE8 with doing previous deleting of all history, cached files and cookies.
Thank you,