This question relates to the discovery of the admin secret url parameter.
I have configured a secret parameter and also added my (fixed) ip to the admin whitelist.
I know that accessing the admin area from my ip circumvents the secret url parameter as I am in the white list, however, I am seeing attempts on the admin page that now include my secret url parameter. These are being succesfully intercepted by admin tools (becasue of the ip whitelist) and logged as security exceptions and blocked.
As my secret url parameter is a long random text string it seems unlikely that this would be guessed, so my question is how are they revealing the parameter?
As access attempts are currently being blocked because of the admin ip whitelist it is not currently a security breach. However, when I travel and need to access the site from other locations, I uncheck the 'allow only access via the admin whitelist' (as I do not know what the ip might be)
In that event, discovery of the secret url parameter is an issue.
Very Best Regards
Graham