Support

Admin Tools

#26744 my Server IP was blocked by Admin Tools

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Saturday, 14 January 2017 17:17 CST

baijianpeng
Recently I re-installed my VPS server software to get PHP7 (formerly it is only PHP 5.6). That means I have to switch from CentOS7 to Ubuntu 16.04, then installed VestaCP which is a web control panel similar as CPanel but free.

Well, then I noticed that in the days after that server installation, I frequently found my website "reject ALL visitors" with following message:

You are a spammer, hacker or an otherwise bad person.



I know this sentence is from Admin Tools, since my website is running Admin Tools Professional 4.0.2 version.

Then I have rename the file "main.php" of Admin Tools via FTP to login in backend.

In the "Admin Tools -> Web Application Firewall -> Auto IP Blocking Administration" I noticed that the IP address of my own server was there!

Look, this is not an IP address of any visitor terminal, but my server itself!

My VPS is using "dedicated IP" , so that IP address does NOT belong to any PC or mobile device of any visitor.

Then I checked the "Security Exceptions Log" and searched my server IP address there, I got following reasons for that single IP:

Admin Query String
Login failure
UploadShield
CSRF Shield


Maybe there were more (more than 10 pages), I did not read them all, just list several here.

I just wonder: Why the IP address of my website server could be blocked?

Does this means that some hacker had broken into my server and use it as a source of attacking terminal?

Is there any option to add my server IP as the "Permanent Whitelist"?

Thank you.

tampe125
Akeeba Staff
Hello,

inside the WAF configuration page, please set the option Enable IP Workarounds to Yes.
Most likely you have a load balancer or reverse proxy in front of your website, so Apache is not reading the visitor IP but your proxy server.
Enabling that option should fix your issue.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!