Support

Admin Tools

#23598 Admin Tools – Geographic Blocking

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Sunday, 29 November 2015 17:20 CST

okkhalid
 Hello,
I have applied the Geographic Blocking too all countries and contents in the world except Canada, as my site is local site and I used to get lots of hits from Russia trying to create membership. so I blocked all countries. it was working fine but I'm still getting some requests to create membership in my site from Poland and Russia ... etc.

Please see attached the blocking page to all countries.
and also see the page today I got 3 requests to register in the site.

Please help. I really want to block any country to visit my site.

Thanks,

okkhalid
I just checked my Google Analytics, and it shows a referral from:

forum.topic69471390.darodar.com

and the area is: Samara Russia

Please help. thanks,

dlb
The GeoIP block is something of a toy. It is good enough to keep the bots out but a live human will go through it like a hot knife through butter. All they have to do is log into a Canadian proxy server and keep on keeping on. Nicholas tried to remove it from Admin Tools a while back but had crowds of users with torches and pitchforks trampling his flower beds, chanting death threats, etc.

Add to that the fact that the geographic data is provided by a third party service based on where the IP is supposed to be. It doesn't know where the IP is, only where the system thinks it is. It is about 90% accurate on a good day.

And hackers don't actually use their own IP addresses anyway. They use computers that they have infected and remote controlled.

So you slowed them down a bit, that's a good first step. Now you need to require user verification to create an account on your site. That is where the user clicks a link in an email sent by your site to verify their information. That kills the rest of the bots because they just can't do that. You can have Admin Tools delete all the unverified user accounts after x days of inactivity to keep your user list clean.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!