Support

Admin Tools

#22940 Setup help

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by dlb on Thursday, 09 July 2015 16:46 CDT

okkhalid
 Hello,

I found there are lots of setting, in the Admin tools, do you have cheat sheet that we can use to setup it probably, because now what I did I just install it and I created the following:
.htacess
and I put admin folder password.

As I assumed it works fine out of the box once we install the component, please help
by the way the user-guide is very long to keep up with it, so I hope you can have a video tutorial or a cheat sheet for dummies like me lol.

Thanks,

dlb
There is really no "one size fits all" solution when it comes to website security.

You may find Brian Teeman's video series helpful: https://www.akeebabackup.com/videos/63-video-tutorials/1550-admin-tools-video-course-with-brian-teeman.html.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

okkhalid
Great thank you :)
The lessons were great thanks to Brian Teeman

dlb
You're welcome!


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

okkhalid
I have activated the IP blocking of repeat offenders
and I got this message today:
We would like to notify you that the IP address 68.144.38.176 is now blocked from accessing your site, until 4753-06-04 19:34:06 GMT.

When I checked the log in the backend, it shows the reason is: tmpl.

I'm not sure is there is any threat in this? also do you have a list of the reasons and description of that.

please see attached.

Thanks,

dlb
The list of reasons is at https://www.akeebabackup.com/documentation/admin-tools/waf-log.html#waf-log-reasons.

Most of these attacks are carried out by automated script files. You'll see some of them trying to execute the JCE editor for example. It is trying to exploit a vulnerability in JCE from back in the Joomla! 1.5 days. If you're running Joomla! 1.5 and the vulnerable version of JCE, yes it is dangerous. But most of us don't have to worry about that any more.

Most of the tmpl "attacks" are along the same lines. Once upon a time there was a template vulnerability that the script is trying to find and exploit. Note that there are a couple of tmpl settings used by your site that need to be excluded from WAF. They are in the documentation for that setting.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

okkhalid
I'm using this templete:
http://demo.rockettheme.com/live/joomla/hexeris/

and Joomla 3.4.3 with the latest JCE

Do you think there is an issue with the Rockecktheme ?

Thanks,

dlb
It really isn't possible for us to keep track of all of the third party software and templates out there and which ones have problems and which versions the problems were fixed in.

You have Admin Tools on the job, that's a good first step. The next step is to keep your Joomla! and extensions up to date so you have the latest fixes for all of the known problems.

Keep in mind that Admin Tools and your security settings are not intended to stop hackers from trying to attack your site, they are intended to keep them from succeeding. You will always see traces in the Security Exceptions Log and the various ban lists. All of this means that you have successfully blocked their attempts.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!