Support

Admin Tools

#18243 Blocking Hacker-Bots permanently

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by tampe125 on Thursday, 21 November 2013 09:33 CST

Baldur2630
 We still have a couple of sites using Joomla 1.5 and the owners don't want to (pay for) and upgrade to 2.x, because they want to wait until Joomla finally reaches a 3.x or higher stability.

I think Joomla made a big mistake (for revenue for website developers) in making 2.0 then 2.5 and then several versions of 3.x in such a short time. Not surprising that customers are reluctant to update.

One of the 1.5 sites had a massive (and I do mean massive) hack attacks, trying to 'guess' the admin password. Almost 1600 computers were involved almost all from Russia and the Ukraine. Normally I would use a Geo Block, but our customer are a Law firm and they actually have business connections in Russia. We had a similar attack, with 600+ computers on one of our other sites, mainly from the USA and Ecuador. Using Admin Tools, I set the ban to 365 days, but I would like to make this PERMANENT.

I tried adding deny from <IP> to the .htaccess, but there are over 200 lines and once added, no-one could access the server. I asked the Hosting company if they could block these parasites on their firewall, but I think they have a vested interest in all these morons sucking up the bandwidth, because "we can't help you".

Is there any way to ban these 2000+ IP Addresses PERMANENTLY without having to add them one at a time to the Site IP Blacklist?

tampe125
Akeeba Staff
Hello Henry,

there isn't an easy way since it's almost useless.
Hackers will change their IP in a few hours, so it's useless and most likely harmful banning them forever.
There is an high chance to block a legimit user that has the bad luck to share the same ip address with a previous attacker, that's why we usually block them only for a couple of days.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!