Support

Admin Tools

#40649 Lots of mails Automatic IP blocking notification for 91.240.118.221

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
4.4
PHP version
n/a
Admin Tools version
7.4.9

Latest post by nicholas on Monday, 06 May 2024 02:47 CDT

pklinke

Please look at the bottom of this page (under Support Policy Summary) for our support policy summary, containing important information regarding our working hours and our support policy. Thank you!

Since 2 days I receive lots of mails from admin tools Automatic IP blocking notification for 91.240.118.221, reason susparm or others.

I have added the IP in the denied IPS, the IP should be blocked automatically but still the mails.

I do not find the IP in the automated blocked IPs

What can I do to finally block this IP?

 

Sincerely

Peter

nicholas
Akeeba Staff
Manager

Regarding the denied IPs, please also make sure you have gone to Configure WAF, Basic Features, and set "Disallow site access to IPs in the IP Disallow List" to Yes. Otherwise, IP blocking will have no effect.

Moreover, you need to update Admin Tools. I believe this will help with the emails as well.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

pklinke

this parameter is the of course.

today another sttack.

what I do not understand is:

there are blocked requests, than IP is blocked and again blocked requests. this game playd over some hours.

After blocking the IP there should be no requests possible, or ?

sincerely

 

 

 

Sincerely

Peter

nicholas
Akeeba Staff
Manager

When a request gets blocked it's just that: only the request gets blocked. This prevents a potentially malicious request from harming your site.

Depending on your settings in the Auto-ban tab (see IP blocking of repeat offenders), a number of repeated blocked requests within a specific period of time from the same IP address will cause that IP address to be temporarily blocked. For example, you may set it up so that an IP address getting 3 requests blocked within 30 seconds will be temporarily blocked for 15 minutes. The idea here is that someone is likely to be a nuisance and you want them to cool off. However, they might also be a legitimate user getting accidentally blocked (false positive), or just doing something stupid; you don't want to block them forever in this case, therefore a temporary and rather short block -- say, 15 minutes -- is a good compromise.

There is a third level of blocking, again depending on your settings in the Auto-ban tab (see Add persistent offenders to the IP Disallow List). You can set Admin Tools up so that when an IP gets temporarily blocked more than a certain amount of times in a specified time period to get that IP address permanently blocked. For example, you may set it up so that an IP address which gets temporarily blocked three times over the course of an hour gets permanently blocked. Do note that this is disabled by default, as we expect you to get blocked plenty of times while setting up Admin Tools for the first time.

You can find the documentation for all these options in https://www.akeeba.com/documentation/admin-tools-joomla/web-application-firewall.html#waf-configure-autoban

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

pklinke

Thanks for your explanation.

But all these settings are known and are set.

 

 

Sincerely

Peter

nicholas
Akeeba Staff
Manager

The Suspicious Core Parameter check preceded the IP block check, hence the reports of the blocked requests. Please use the following dev release: https://www.akeeba.com/download/admin-tools-professional/7-5-4-dev202405020613-rev9774909a.html

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

pklinke

Oh, thank you for information..

But I'm afraid to install an alpha version on a live system when I'm far away from home. If something goes wrong, I am reduced in the possibilities to repair.

 

Sincerely

Peter

nicholas
Akeeba Staff
Manager

OK, then. You can wait until the exact same code is released with a "stable" label.

Closing as fixed.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!