Support

Admin Tools

#16865 Template in URL: mailto exceptions question

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Wednesday, 24 July 2013 12:38 CDT

neilw
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? Yes
Have I searched the tickets before posting? Yes
Have I read the documentation before posting (which pages?)? Yes
Joomla! version: (2.5.9)
PHP version: (5.3.26)
MySQL version: (unknown)
Host: (optional, but it helps us help you)
Admin Tools version: (2.5.6)

Description of my issue:

I read the thread about the security exceptions for http://samplewebsite.com/index.php/component/mailto/?tmpl=component&template=themeXXX&link=2aba20fb705f7b3c29d45bb74d5d8744c1b7dc21

On one of our websites, we are now routinely getting this security exception. In reading the thread ( #10939 – How to read Security Exceptions Log https://www.akeebabackup.com/support/admin-tools/10939-how-to-read-security-exceptions-log.html ), it sounds like it is simply an attempt to use the Send to a Friend feature in Virtuemart or Joomla (??). However, we have that feature turned off on that site, so no one could be legitimately attempting to use it.

Given the non-USA IP's that are causing these security exceptions, it makes me wonder if they are trying to exploit the website to send spam??? None of the IP's match an actual visitor IP (using Joomlawatch to track visitors), nor do they match know crawlers/Bots (Google, etc.). Checking the whois on these exceptions shows them to be likely hackers.

Is my assessment correct or am I misreading this and the other info on your support site?

Thanks. Really like your software.

nicholas
Akeeba Staff
Manager
If you have that turned off on your site, the attacker is probably trying to exploit a bug in a very old version of Joomla! which allowed him to use that URL to send spam. That's been long fixed. You're safe leaving that feature enabled on your site.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!