Support

Admin Tools

#29057 Admin Tools

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Thursday, 01 March 2018 17:17 CST

user10843
Getting the following after the installation on my site:

We would like to notify you that a security exception was detected on your site, [SiteName], with the following details:

IP Address: [ip Address] (IP Lookup: IP Lookup)
Reason: Admin Query String

This exception is a nusiance and I cannot seem to eliminate. I have no problems logging into my site etc as administrator and I'm the only one accessing it.

Regards,
Scott

nicholas
Akeeba Staff
Manager
I understand what you are saying, but just because you are the only Super User on your site doesn't mean that hackers don't try to access it and break into it anyway. When they do, since they don't know the secret URL parameter for the administrator page, they raise this security exception. In other words, Admin Tools just told you "hey, Scott, I just caught another clown trying to break into your site".

If you don't want to receive that message there are three ways to go about it.

The best method is to use the Password-protect Administrator feature in Admin Tools. This creates a web-server-level protection which you need to go through before PHP even loads. Since the attackers won't get past it the security exception in Admin Tools won't be triggered.

The second method is disabling the email message for this security exception. Go to Admin Tools, Web Application Firewall, Configure WAF and click on the "Logging & Reporting" tab and find the "Do not send email notifications for these reasons" option. Add "Admin Query String" and click on Save & Close.

The third method is disabling the administrator secret URL parameter from the Configure WAF page but I don't recommend it. The whole point of using Admin Tools is to improve security of your site. Disabling features won't help with that. I just include this option for completeness.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user10843
Hi Nicholas,

Thanks for the reply. I now understand the rules. I'm a big fan of Akeeba Backkup and thought I'd give Admin Tools a try as an alternative to RSFirewall. I'll continue with my evaluation - so far I like what I see.

CHeers,
Scott

nicholas
Akeeba Staff
Manager
You're welcome, Scott! I am glad I could help you :)

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!