Support

Admin Tools

#15692 security exception

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Tuesday, 09 April 2013 10:15 CDT

user74654
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? yes
Have I searched the tickets before posting? yes
Have I read the documentation before posting (which pages?)? No
Joomla! version: (2.5.9)
PHP version: (5.3.21)
MySQL version: (5.5.30-cll)
Host: (linux)
Admin Tools version: (Admin Tools Professional 2.5.3)

Description of my issue:

Hi there

I installed Admin Tools Professional 2.5.3 and set up all the required setting in teh quick-sart , I thought I would have a peace of mind..

The site was just launched less than 24 hours and I started to get "security exception was detected on your site" emails

I looked at the first few IP's and I blocked then in the "WAF" blacklisted IP

still getting emails about teh same IP's
so I blocked an IP's range
still getting emails about security exception was detected on your site

I then loged into the Cpanel and I blocked these IPs
and it stops getting me these emails

then 12 hours later I revived almost 146 emails almost 10 of them had
"Reason: Admin Query String"

and the rest are "
stating :security exception was detected on your site and these had " Reason: template= in URL"

So, I don't know is the whole world is trying to hack my site
or is it some setting I configured wrongly !

nicholas
Akeeba Staff
Manager
You can do something different and much easier. Use Admin Tools' feature which allows you to automatically ban repeat offenders. It's in the Configure WAF page and is mentioned in the Quick Setup chapter of our documentation.

The exception you get means that someone is trying to access the backend of your site (the administrator URL) without providing the secret URL parameter. As a result a security exception is generated when Admin Tools block him.

The fact that you launched your site just 24 hours ago doesn't say anything. Attacks may start anytime and go on pretty much forever. That's why I built Admin Tools in the first place :)

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user74654
I LOOOOOOOOOOVE YOU Nicholas,

I just did what you mentioned

one more question please,
on the tab "Security Exceptions Log"

some IP had a red square and some had a Green square,

To BAN an IP should I click on the Green or the RED to BAN an IP?
it is a bit confusing ...sorry
I swear ( page 47 of the manual PDF) as my admin tool Pro, interface is not like the one in the manual.
( see attached screen shot)
Thanks a million

nicholas
Akeeba Staff
Manager
The screenshots may be a little outdated. I didn't have time to update them for a long time.\

Regarding your question, the red button means "it's not blocked, click me to block this IP". The green button means "this IP is blocked, click me to unblock it".

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user74654
Thank you
Thank you
Thank you

Again. I love you man, you are Z BETS


God Bless


Case Closed :)

nicholas
Akeeba Staff
Manager
You're welcome :)

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!