Support

Admin Tools

#28204 10.10.111.x in exceptions log

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Friday, 01 September 2017 17:17 CDT

PTWD
I've reported a version of this issue before. My apologies for sounding like a broken record, but this time it's a bit different. Starting yesterday, I suddenly started getting a private network IP (10.10.111.x) showing up in the Admin Tools exceptions log---but only some of them.

In the past, all of the exceptions were this IP and it was fixed by changing the "enable IP workarounds" setting. This time, only some of the IPs in the exceptions log are from 10.10.111.x and the rest of normal-looking IPs. Therefore, it doesn't seem to be related to the IP workaround setting.

It doesn't seem to be a problem at this point (I'm not being blocked, myself, for instance) but I'm really puzzled why this would be happening if it's not caused by the IP workaround setting. And since I had problems a few months ago with the setting apparently being reset without me doing it, seeing this IP number again in the log makes me very nervous. I am the only person who uses admin access to the site, so I don't see how it might be another person involved with the site, and as far as I can tell we haven't been hacked.

When you get a moment -- no rush since it's not an actual problem (yet?), just a puzzle -- could someone please hazard a guess as to how and why these are showing up again, but this time only with some of the exceptions? It started yesterday and there have been 7 exceptions since then, so it wasn't a one-off.

Many thanks!

nicholas
Akeeba Staff
Manager
I would need to know a lot about your server and network setup to even entertain the idea of hazarding a guess.

I can infer that you have a "something" in front of your actual server, where "something" is a CDN, proxy or even NginX acting as a reverse proxy to Apache (or whatever web server software you are using). Does it generate correct X-Forwarded-For headers?

If there is a chain of them or someone is screwing around with the X-Forwarded-For headers I'm pretty sure it won't work correctly. There is a bug in the workarounds code which was fixed in FOF 3.1.2 (the library powering all of our software, part of which is also the IP handling code) released yesterday. Upgrade to it. If Joomla! doesn't show you the upgrade, download and install it manually, on top of the existing version.

Also, if you are using Sucuri's firewall you would have this problem. They seem to shun the web standard X-Forwarded-For header, using their own header with the same functionality instead. Another thing we addressed in FOF 3.1.2.

Finally, you could have a third party plugin messing up with the IP address seen by the server.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!