Support

Admin Tools

#33063 Admin Tools settings

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Thursday, 18 June 2020 17:17 CDT

kendallcc
I have replaced RSFirewall with Admin Tools because I wanted a better way to protect the access to our admin area and also because of the excellent reviews from others.

I must admit, however, that I am a little overwhelmed. I've been getting so many security exceptions emails like:
template= in URL, 404 shield, Admin Query String, SQLi Shield, auto-banned IP address. What does it all mean? Do I have to take any action? Today I got blocked twice while working on my creative slider component and I do not know why. Was it something that I did?

I am confused. How can I learn how to properly setup Admin Tools without getting freaked out every time I get a notification from Admin Tools?

Thank you!

nicholas
Akeeba Staff
Manager
Admin Tools is designed to block all sorts of attempted attacks, including those that have a very low to non-existent chance of success. By default, it emails you for everything it blocks – I personally find this useless but the majority of our clients asked for it, hence this being the default.

The first thing I recommend is going to Components, Admin Tools, Web Application Firewall, Configure WAF and remove your email from all settings in the Logging & Reporting tab. Except maybe "Email this address on failed administrator login" because that's something you should be aware about.

Now regarding you getting blocked. It was probably because of something you did but we can work around it if we know what it was. Once you get blocked follow the unblocking instructions and then go to Components, Admin Tools, Configure WAF, Security Exceptions Log. Look for the entry towards the top of the list that has your IP address in it. If you're not sure what your IP address is just go to https://whatismyipaddress.com to find out. You will see that the Security Exceptions Log entry has a Reason and a Target URL. The reasons are explained in the List of Blocking Reasons documentation page. They tell you which is the relevant setting. If you can't figure it out yourself please start a new private ticket and give us the Reason and Target URL and tell us what you were doing when that happened so we can help you.

Configuring Admin Tools takes a bit of trial and error at first but it can be tailored exactly to your needs and how your site is set up. The learning curve is a bit steeper than other security extensions but once you configure it for your site it will protect you much better.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

kendallcc
Hi there. I've followed your advice and removed my email from all notifications, just left the back end login stuff.

Today I got locked out again. I was working with the component Creative Slider and left the computer to do something else. When I came back and tried to resume work, I got a message saying that it timed out. A popup window with the front end appeared and I closed it by clicking on the X. That's exactly when I got a message from Admin Tools calling me a bad person.

Thank you!

nicholas
Akeeba Staff
Manager
When I came back and tried to resume work, I got a message saying that it timed out. A popup window with the front end appeared


That solves the mystery, even if you didn't give me the information I originally asked for :)

You have enabled the Administrator Secret URL Parameter feature. When you access the administrator of your site as /administrator/index.php?YOUR_SECRET_PARAMETER_HERE Admin Tools sets a flag in your user session which says "yup, this person knows the secret URL parameter". This allows you to see the backend interface, including its login page.

If your user session expires this flag is no longer set. Any attempt to access a URL in the backend (/administrator) of your site will trigger a security exception and redirect you to the frontend of the site. If you trigger too many of them – per your Admin Tools settings – you will be locked out of your site.

By leaving your browser tab open for a period of time longer than the Session Timeout (as defined in your site's Global Configuration) your session does expire. When you tried going back there the component you were using tried to access a URL in the backend of your site, repeatedly, triggering the security exception and redirecting you to the frontend of the site. Hence the frontend page in the popup. That's how you got blocked.

The solution is simple. Do not leave your browser open to your site's backend. Log out instead.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!