Support

Admin Tools

#30223 Feature Request

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by dlb on Monday, 10 September 2018 11:36 CDT

UglyEoin
Please look at the bottom of this page (under Support Policy Summary) for our support policy summary, containing important information regarding our working hours and our support policy. Thank you!

I have a site which is getting 6,500 exceptions in 30 days. But when I review the exceptions log I see lots of patterns. I would like to request a few features.

(a) I would like to be able to bulk blacklist some IP addresses as they are all very similar (first three numbers are the same, last number changes). There are also some patterns e.g.

/--cox_sym/root/homepages/14/d121902034/htdocs/pertermaclean/xmlrp.php?x=chmod&f=media&d=%2F

My hosting user/folder is not /pertermaclean/ so whatever hosting they are looking for it is not mine. However, this site was taken over from a hacked site, and that URL does appear in Google under our domain name so perhaps it existed on the old site.

I don't know if you have any advice on that? Or as to whether my IP address solution is not the smartest.

(b) I would like to be able to search the URL in the blacklist. That gives me more of a clue than the IP address.

(c) I would like to make some rules. e.g. wp-login wp-admin. These are WordPress URLs (as I'm sure you know) so anyone accessing them on Joomla! is probably a bot trying to work out how to hack the site.

Because of the sheer volume of emails I've reduced the email numbers in Admin Tools, but should I be taking other more proactive action do you think?

dlb
It is possible to import IPs into the blacklist, but it isn't a good idea. Hackers don't use their own IP addresses, so you're just blocking a dynamic IP at an ISP or an open proxy server, etc. Temporary blocks are better because they slow down the attacker without permanently disabling the IP address.

Why not just add "/pertermaclean/xmlrp.php" to the list of URLs that 404 Shield will flag as a security exception? That will allow you to use your auto ban settings to block the IP addresses being used.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

UglyEoin
Great suggestion. Thanks. I'll do that.

dlb
You're welcome!


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!