Support

Admin Tools

#21885 project honeypot threat level

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Friday, 16 January 2015 11:05 CST

speru
 Hi
Just a quick question to clarify:
I have enabled HTTP:BL filtering with the threat level to block set really low at 8
Daily I see the blocked access to ip's above this threat level so all appears to be working well.
However, using Content Statistics I can see all visits to the site and the pages they are visiting.
I noticed a high level of traffic from Ukraine and investigated further.
In the past two days I have had 86 visits using 6 different IP addresses. The Ukrainian IP addresses are typically in the region of threat level 45, but none of them appear on the Admin Tools security exceptions log, whislt other ip's from elsewhere are being blocked with lower threat levels.
I know that I could block all access from Ukraine, but wanted to ask for some clarification as to why known spammer ip addresses are able to browse the site without an exception being created by Admin Tools.

Many thanks Graham

nicholas
Akeeba Staff
Manager
Admin Tools will only block an IP address if Project Honeypot replies that it has a threat score higher than your threshold and that it's of an interesting type (see http://www.projecthoneypot.org/httpbl_api.php). If it's marked as only a suspicious IP (flag 1 set) and you've not chose to block suspicious IPs then no, they won't be blocked.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

speru
Yes I have suspicious IP's checked.
The answer is the maximum age of accepted HTTP:BL results, which I have set at 100 days.
If you were to check 91.207.8.46 you would see that although the threat rating is 50 the Spider Last Seen is 2014-12-04 and Project Honeypot comments: "This IP has not seen any suspicious activity within the last 3 months. This IP is most likely clean and trustworthy now." (Although we know that it isn't, and just hasn't been caught again yet.)
I am confident that Admin tools will quickly block the IP if there is any malicious attempt on the site.
I feel a Ukrainian Geo block coming on as it ruins the site stats with so many nefarious visits.

Great tools guys, would be in a World of pain without them.

nicholas
Akeeba Staff
Manager
Yes, I forgot about the maximum age. Doh! For your information, after about 30 days the results are likely to be out of date. At 60 days without activity the IP is most likely clean. At 100 days the possibility of the IP being still used by a spammer is virtually non-existent.

And thank you very much for your kind words! Have a nice weekend :)

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!