Support

Admin Tools

#17470 Automatic IP blocking doesn't seem to be working

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by erixis on Monday, 23 September 2013 07:35 CDT

erixis
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? yes
Have I searched the tickets before posting? Yes
Have I read the documentation before posting (which pages?)? Yes IP blacklisting and Security Exceptions Log
Joomla! version: 2.5.14
PHP version: 5.3.13
MySQL version: 5.0.37-standard
Host: phpwebhosting.com
Admin Tools version: 2.5.8

Description of my issue: I am having occasions where admintools emails me multiple warnings (50 or more sometimes, on a few occasions over 100 times) notifying me of failed administrator access. I have the .htaccess set for the administrator log in, as well as the WAF set to automatically block an IP that offends repeatedly (5 times in 10 minutes) and to block that IP for 30 minutes. The emails would indicate that this offender (same identical IP) is attempting every 30 to 60 seconds. If I log in and manually put this IP in the blacklist, it stops, but I thought that Admin Tools would stop it automatically if trying at that rate. Also, if the .htaccess is working, how are they getting to the admin log in screen unless they've guessed my htaccess log in credentials. I've never given them to anyone. I am the only admin for this site. The IPs are usually Ukrainian. I don't know anyone from the Ukraine and this site doesn't serve anyone internationally.

I am changing passwords and usernames as a response to this, but just wanted to know if there is a way to block these more effectively in the future.

Thanks
Eric

nicholas
Akeeba Staff
Manager
This email is sent before the IP block ultimately blocks the user. It's a small quirk of how Joomla! and Admin Tools works. That said, you are protected. Even if the attacker guesses the correct username/password they will still be denied access.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

erixis
Thanks Nicholas

Eric

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!