Support

Admin Tools

#28892 Administrator Login Protection Issue

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by dlb on Saturday, 16 December 2017 12:42 CST

4FootyFans
Hello

Apologies if this has been answered previously.

Ok, I just installed AdminTools Pro.

Followed the Setup Wizard

Assigned a username + password to protect Administrator area.

The problem is that having entered the htpasswd username+password, I can only load the site front-end.

No error message.

I needed to rename the plugin in order to re-gain backend access.

I have read a thread re 401 error.

Is that the problem or a different issue?

TIA

dlb
Something isn't right. If the problem was with the user name and password prior to the login page, renaming the plugin would not solve it. Those are completely different things. The way to disable the user name and password layer is to rename or delete the .htaccess file in the /administrator folder. The plugin isn't loaded at that point.

Can you please give me some more details on exactly what you see when you try to log in?


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

4FootyFans
Hello Dale

I only renamed the plugin so that I could access the backend again.

The htpasswd username + password were fine.

From recollection, I had the same problem when trying to protect the Administrator directory via cPanel.

TIA

dlb
Let's take a look at something else. In Web Application Firewall, Configure WAF, on the first tab, what is the value of the "Administrator secret URL parameter" field? If there is a value there, you have to call your back end login with the URL:
www.mysite.com/administrator/index.php?secret
Where "secret" is the value in that field. If you don't use the secret parameter, you are redirected to the home page. The theory is that if the bad guys can't find your login page, they can't try to log in.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

4FootyFans
Aha!

That makes sense.

I am away at the moment but will try it later and report back.

Thanks for the quick responses and advice.

Best
Eddie

4FootyFans
Hi

Problem solved.

Thanks

Eddie

dlb
You're welcome!


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!