Support

Admin Tools

#13266 Attacks from Japan IP's

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Wednesday, 15 August 2012 06:19 CDT

user54642
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? Yes
Have I searched the tickets before posting? Yes
Have I read the documentation before posting (which pages?)? Yes
Joomla! version: 2.5
PHP version: 5
MySQL version: (unknown)
Host: (optional, but it helps us help you)
Admin Tools version: Latest

Description of my issue:
Hi for the last six months I have been attacked by the following range of IP's 150.70.*.* from Japan. I have just updated a website to Joomla 2.5 and the first thing I do is install Admin Tools. Within minutes I was seeing the following entries in security exceptions log:

http://domain/administrator/index.php?option=com_admintools&view=logs
http://domain/administrator/index.php?option=com_admintools&view=ipautobans
http://domain/administrator/index.php?option=com_admintools&view=ipbls&task=add
http://domain/administrator/index.php?option=com_login&task=logout&f95034e145e48ec4f2c0654ec2ea54bd=1
http://domain/administrator/index.php?option=com_installer&view=update&task=update.ajax

I am right in thinking this an automated attack as it always seems start within minuets.
They know I am using Admin Tools but do not know the secret work for backend access so what exactly are they trying to do here?

Thanks
John

nicholas
Akeeba Staff
Manager
Well, those URLs make no sense. They are in the administrator directory which means that in order to get to them you have to know the administrator secret URL and the Super Administrator username and password. Seeing the logout URL in the mix I'm thinking that it's not a hacking, it's a website indexer from some search engine (without the exact IP I can't be sure). Do you have any toolbar or SEO extensions installed in your browser?

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user54642
Thanks for the quick reply Nicolas, as normal :-))

No, I never use toolbars, not sure what a SEO extension is but I tend not to install browser extensions.

Regards

John

nicholas
Akeeba Staff
Manager
Well, I have to admit this is a strange selection of URLs for a hacking bot :) It would only make sense if someone already had compromised your site. It would then make it possible for the attacker to automatically unblock his own IP and block you instead. Well, I'm not sure what it is, but letting Admin Tools auto-ban this IP sounds like a great idea :)

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user54642
Already blocked them.

Thanks

John

nicholas
Akeeba Staff
Manager
You're welcome, John!

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!