Support

Admin Tools

#28066 Email after adding new Super User

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Friday, 04 August 2017 17:17 CDT

[email protected]
Hello,

after adding a new Super User in the backend I get all five minutes an email "Super Users were added to ÖGS.AT". (text see below)

Unfortunately I cannot find an option how to tell the system that this is OK and this user is wanted.

Hello,
We would like to notify you that we detected the suspicious addition of one or more Super User accounts to your site, ÖGS.AT. These new Super User accounts do not seem to have been created through the regular means, i.e. Joomla's “Users” page. Therefore they have been blocked. The new Super User accounts detected and blocked are:
• #705 – gabriele – Gabriele Banagl <[email protected]>
Do I need to worry?
Super User accounts have full access to your site. They can modify all content, without any restriction. They can also install software which can access or modify every aspect of your site, including arbitrary files, database content and configuration settings. Only grant Super User access to people you trust.
If you are receiving this email it means that these Super User accounts were created outside Joomla's “Users” page. Typically this means that a hacker found a way to bypass your site's or your server's security and tried to surreptitiously create Super User accounts for themselves. For this reason these accounts were blocked, i.e. they cannot be used to log into your site.
It is possible, however, that you do receive this email in error: if you or another Super User did intend to create these Super User accounts and used a third party tool to do that. If this is the case then do not worry. Just log in to your site's administrator backend with your own Super User account, go to the Users page, edit the users listed further above in this email and unblock them.
If you or another Super User did NOT intend to create these Super Users we recommend auditing your site and your server for any other signs of anomalous activity.
Best regards,
The ÖGS.AT team

nicholas
Akeeba Staff
Manager
Components, Admin Tools, Web Application Firewall, Configure WAF, Joomla Feature Hardening Options, Monitor Super User accounts.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

[email protected]
Thx for quick answer. But this don´t answer my question. This is the option where I can turn it on and off generally.
I do not understand why admin tools didn´t accept the new super user as a good one. I put in all user information in the Joomla backend.

Regards
Thomas

nicholas
Akeeba Staff
Manager
If the new Super User is created outside of Joomla!'s Users page this email is triggered.

The way Admin Tools determines whether Joomla's Users page was used or not is the $context variable sent by Joomla to user plugins when the user save event is triggered. If that doesn't match what Joomla's Users page should send we raise a security exception.

Why would that email be triggered from the backend of your site? There are a few possibilities.

You are using a different component, not Joomla's Users page. For example, some e-commerce and community management software have their own user management pages which circumvent Joomla's Users page.

Silent hijack by a plugin. This could happen if a system plugin is hijacking your attempt to use Joomla!'s Users page and instead diverts you to a different component.

A bad plugin screws up the context. If you are 100% sure you're using the Users page, the explanation lies in the immortal words of Robert J. Hanlon: "Never attribute to malice that which is adequately explained by stupidity". A user or system plugin author may have inadvertently written code which modifies the context during the plugin event execution.

The first two possibilities is exactly what a hacker would do to get your site report to them all information about Super Users created on your site and/or create a bypass to Joomla's security checks. The third possibility is just a broken plugin.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!