Support

Admin Tools

#17582 Attacker uses some kind of masked address

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by dlb on Thursday, 19 September 2013 08:28 CDT

user73275
Mandatory information about my setup:
Have I read the related troubleshooter articles above before posting (which pages?)? Yep
Have I searched the tickets before posting? Yep
Have I read the documentation before posting (which pages?)? Yep
Joomla! version: 1.5 (I know, upgrade is underway)
PHP version: 5.2.17 (newer version with new joomla)
MySQL version: 5.6.12
Host: www.koduhaldus.ee
Admin Tools version: 2.2.10 Pro.

Description of my issue:
AdminTools sent me a warning - IP Address: 2a00:1ca8:4e::149 (IP Lookup: http://ip-lookup.net/index.php?ip=2a00:1ca8:4e::149)
Reason: Login failure (Username: admin -- Password: 123456)

That is obviously not the correct addfress but somehow masked. Is there a way to block this from acćessing altogether or should I just wait it out until the bot goes out of preconfigured passwords? What is that IP address and how could it be named (to google more about it).

Thank you if you have a sec to drop me a line on this. It really is not a version specific problem, but rather a generic one, how to behave in the future when this type of attack occurs.

user73275
I feel quite stupid now - it is obviously an IPv6 address. I guess I panicked when the exceptions started coming in. I will accept if that old version of software this particular server is still using, cannot deal with ipv6 address space. It seems the IP-blocking is not working with that address. But now that I know what it is, I will monitor the situation for a day.

I hope this post will be helpful for those DIY-webmasters who have not seen an ipv6 address bedore :)

dlb
I'm glad you figured it out. The IP6 addresses are not yet supported in the Admin Tools blacklist. Support will be added as the addresses become more fully supprted by commercial hosts.

Dale


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!