Support

Admin Tools

#17595 WAF Autoban problem

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by dlb on Friday, 20 September 2013 10:22 CDT

drjjw
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? Yes
Have I searched the tickets before posting? Yes
Have I read the documentation before posting (which pages?)? Yes (https://www.akeebabackup.com/documentation/admin-tools/web-application-firewall.html#waf-configure)
Joomla! version: (2.5.14)
PHP version: (5.3.27)
MySQL version: (5.5.32)
Host: (Liquidweb)
Admin Tools version: (2.5.8)

Hello,

I have WAF configured to autoban repeat offenders after 7 infractions within an hour. As you will see in the attached log, I visitor has been attempting a query string on the admin panel and does get autobanned for 1 day according to the admin tools email I am sent, but arrives very shortly after with the same infraction. This then triggers another email notification but still, the user returns.

Log attached.

https://www.dropbox.com/s/y9lxfmf7z8t1z77/WAF%20Log%20.xlsx

Settings attached:

https://www.dropbox.com/s/2pln13vog81sol7/Screen%20Shot%202013-09-20%20at%205.54.46%20AM.png

dlb
Jordan,

Under Web Application Firewall, Configure WAF, at the top under Basic Protection Features, the Disallow site access to IPs in Blacklist setting must be set to Yes.

Dale


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

drjjw
Ah, ok.

Thanks Dale, I see that.

dlb
You're welcome!


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!