Support

Admin Tools

#15014 tmpl= URL security exceptions, mailto-URLs, icons hidden

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Wednesday, 13 February 2013 06:48 CST

formfranska

Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (Exceptions, Security Exceptions Log, Chapter 2. Using Admin Tools, What is Bad Behaviour, why do I receive emails about it by Admin Tools and what does it mean?, Web Application Firewall, Server protection)? YES
Have I searched the tickets before posting? YES
Have I read the documentation before posting (Chapter 2. Using Admin Tools)? YES
Joomla! version: (2.5.9)
PHP version: (5.3.13)
MySQL version: (5.1.66-cll-lve)
Host: (www.oderland.se)
Admin Tools version: (2.4.4 Pro)

Description of my issue:

To me the security exception tmpl= URL is somewhat difficult becasue I'm not sure when I should take action (block an IP).

What your wrote here was extremely helpful

https://www.akeebabackup.com/support/admin-tools/14709-many-security-exceptions-for-reason-tmpl-in-url.html

<quote>
A hacker will use the tmpl= URL parameter for fingerprinting. Let's say I don't know if your site is using Joomla!. I will take a regular URL and pass tmpl=gobbledygock. If I see the template reverting to one of Joomla!'s built-in templates I know that you're using Joomla!. Based on some things in the HTML of the template I might even understand which version family (1.5, 1.6, 1.7, 3.0) of Joomla! you're using. This is not the only way to do that, it's just one of the most popular.
</quote>

My assumption:
So that probably means I could rule out the tmpl= URL security exceptions that have, for example
component/mailto/?tmpl=component&template=template_name
in the URL as harmless? Cause they would be caused by the “mailto icon” in articles?

Question:
But still - why am I still getting these security exceptions with URLs like
mydomain/component/mailto/?tmpl=component&template=my_template&link=xxxxxxxxxxx
even though I've set all icons in article manager options to HIDE?

And should I block IP's causing this security exception (template= in URL, with "mailto" in the URL)?

This applies to 3 different websites where I've set all icons in article manager options to HIDE.

Thank you for your great extensions Nicholas :-)

nicholas
Akeeba Staff
Manager

You missed the documentation page where I talk exactly about this case, under "Allow site templates" :) The security warnings you get have to do with the template= blocking feature of Admin Tools. You just need to enabled the "Allow site templates" feature to fix that.

FYI, even if you hide all the icons in the article manager, the com_mailto component (and the "Send article by email" feature it provides) is still available. That said, if you've hidden the icons my guess is that someone is trying to exploit a very old bug in a very old version of Joomla! where it was possible to abuse com_mailto to spam other people.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

formfranska

Hello Nicholas,

Thank you! No, I did read about the "Allow site templates" feature in the docs and also in other tickets :-) But, I don't dare to have it set to YES. If I did (as far as I can understand it) I wouldn't be warned when someone tried the "fingerprinting trick" for example.

But now you've calmed me down anyways :-) since I gather someone is just trying to exploit a very old bug in a very old version of Joomla! My conclusion: I'll let them waste their time!

Cheers :-)

nicholas
Akeeba Staff
Manager

You're welcome, Anna!

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!