Support

Admin Tools

#32568 WAF blocking URL but why?

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by RRO on Thursday, 27 February 2020 03:24 CST

RRO
Hi Overthere,
I use Websiteauditor, which is part of Linkassistants SEO-Powersuite. This tool crawls the pages and looks for problems regarding meta, content, structure, and many other things.

When doin' so AdminTools kicks in and blocks access with "template= in URL" status. Can I see anywhere which part of the URL was triggering the block?

Example:
https://client.com/component/mailto/?tmpl=component&template=xyz&link=599df174a5e5aa9dc8025dfc50665c97adad7e03


Additional Question: Is there a way to only temporarily whitelist my actual IP e.g. for the actual scan procedure?

nicholas
Akeeba Staff
Manager
Look at the URL closer, you'll see the template= in it as the message tells you:

https://client.com/component/mailto/?tmpl=component&template=xyz&link=599df174a5e5aa9dc8025dfc50665c97adad7e03

If you are using the Mail To feature in Joomla you can enable the "Allow site templates" option per our documentation.

Additional Question: Is there a way to only temporarily whitelist my actual IP e.g. for the actual scan procedure?


Yes, of course. Web Application Firewall, Configure WAF, Exceptions, Never Block these IPs. Add the IP address where the requests will be coming from in there. Remember to remove it once you're done.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

RRO
Hi Nick,
#1 did the trick.

Thx a lot,
Ralf

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!