Support

Admin Tools

#40596 addresse IP

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
5.1.0
PHP version
8.1
Admin Tools version
7.5.1

Latest post by Pimpouze on Wednesday, 24 April 2024 04:11 CDT

Pimpouze

Bonjour,

J'ai un souci sur un site avec un hacker qui tente de le pirater, avec une IP 127.0.0.1, ce qui fait que même moi, je suis bloqué par mon site.

Comment pourrais-je bloquer cette personne, sans que je sois bloqué moi-même. Bien que mon adresse personnelle soit en liste blanche.

Cordialement

 

Hello,

I have a problem on a site with a hacker trying to hack it, with an IP 127.0.0.1, which means that even I am blocked by my site.

How can I block this person without being blocked myself? Even though my personal address is whitelisted.

Sincerely

 

tampe125
Akeeba Staff

Hello,

127.0.0.1 means that the source is "localhost" so it's the server itself. This of course is not possible, most likely your server has a proxy in front of it, so you have to tell Joomla to look for the correct IP address.

Please get inside Joomla Global Configuration and enable the option "Behind load balancer". That should do the trick.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Pimpouze

Hello,

Thank you for your reply.

I've done what you asked, but unfortunately he's just made a few more attempts, which has blocked me too.

Sincerely

tampe125
Akeeba Staff

mhm... there's a chance that the host is not configured to properly. Can I connect to your site to I can run some tests?

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Pimpouze

Yes, how do we do it?

tampe125
Akeeba Staff

I have made this ticket private so that only you and me can see the information posted here.

Please provide me with the following information:

  1. The URL to your site's administrator login page
  2. Super User username and password
  3. FTP connection information


Please allow up to one business day (GMT+2 timezone) for me to log in to your site and debug this issue. When I'm done I will post back. Once the issue is fixed, you can revoke my access e.g. by changing the Super Administrator and FTP passwords.

IMPORTANT INFORMATION
In order for me to help you fast and accurately, please provide the information by copying the form below, paste it into your reply and fill in the information:

----- Access Information Form -- START -----
Super Administrator access

  • URL to site's administrator page (e.g. http://www.example.com/administrator?foobar):
  • Super User username:
  • Super User password:


FTP connection information

  • FTP methods supported (e.g. FTP, FTPS, SFTP):
  • FTP Hostname:
  • FTP Username:
  • FTP Password:
  • FTP Port (if other than 21 for FTP and 22 for SFTP, ask your host):


----- Access Information Form -- END -----

Please make sure that you have tested the Super Administrator connection using a different browser or machine than the one you are using daily. Double check that logging in is possible and that the user has Super User privileges, i.e. it's not a regular Administrator. Make sure that your site does not block whole countries or IP ranges which would make it impossible for me to log in / connect by FTP. Finally, please do make sure that the FTP connection works and that logging in to it I have access to your site's files.

Kindly note that your site connection information and your site content is handled in strict confidence. Not only we are a reputable development company, we are also bound by law (EU GDPR) to do so. After you file your reply, the connection information to your site will be stored in an encrypted, hidden storage area on our site and will be automatically deleted when this ticket is closed. Finally keep in mind that the people providing support to you are the same developers who wrote the software you're using on your site.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Pimpouze

Hello,
Here is a message from AdminTool:

I can no longer navigate in the administration. That's going to complicate things because for the administration, I've set up the exclusive Super admin address.

tampe125
Akeeba Staff

Please manually disable Admin Tools as explained here to regain access: https://www.akeeba.com/documentation/admin-tools-joomla/web-application-firewall.html#help-locked-out 

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Pimpouze

https://himalaya-arch.com/

Login to admin site :

Identifiant:                 Web2019@admin_himalaya-arch
Mot de passe:                Admin_Pimpouze@93200*

FTP connection :

FTP user name : himajckh
Server : ftp.himalaya-arch.com
Port : 21
Password : mE3wzTxZ8JYvrX

Sincerely

 

Pimpouze

I have access to administration for the moment.

If I rename provider.php, the site will no longer be protected. I'm waiting for you to take action.

Sincerely

Pimpouze

Site password : Admin_Trucmuche@93200* and not Admin_Pimpouze@93200*

tampe125
Akeeba Staff

Can you please double check your FTP password? I'm trying to login but it says that the password is incorrect.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Pimpouze

FTP user name (login): himajckh
Serveur (host): node51-eu.n0c.com
Port : 21
Password : FRCEXxphwbv12U

tampe125
Akeeba Staff

Thank you very much for access details, I was able to login. I reviewed your settings and everything seems ok.

When you get blocked, can you please disable Admin Tools and then take a screenshot of the Blocked Requests Log? So we can understand what is triggering the security exception

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Pimpouze

Hello,

Thank you for your reply.

When I'm blocked, the only message I get is :  We have detected suspicious activity from your IP address. Your access to this site is temporarily suspended.

Sincerely

 

 

tampe125
Akeeba Staff

That is pretty strange, how are you connecting to the server? Are you working on the same server that is hosting your website?

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Pimpouze

Hi,

Non,

This is the server of the site host, Planethoster. And the hacker uses the address 127.0.0.1. How is this possible????. But maybe a virtual host.

Sincerely

 

Pimpouze

Hello,

I'm coming back to you because I've just tried to delete an entry and got blocked (see the two screenshots).

Best regards

tampe125
Akeeba Staff

mhm... there's something strange in this kind of requests. I enabled the creation of a log file. Next time you get blocked, can you please page me so I can take a look at the log file?

I suspect there's some kind of cache being involved.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Pimpouze

Ok,

Which log, from the Joomla system? Which log?

tampe125
Akeeba Staff

Admin Tools log. But there's no need for you to take a look into it, since there are a lot of extra information. Simply page me when this happens again.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Pimpouze

Hello,

On https://himalaya-arch.com, not today.

But on another site, it's: 2001:41d0:1004:56::1

Impossible to locate or block.

Best regards

tampe125
Akeeba Staff

Since I have activated the log on the website https://himalaya-arch.com/ , please page me when it happens there.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Pimpouze

OK, thanks for your help

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!