Support

Admin Tools for WordPress

#40168 Ticket #40162 Security Exceptions Log question -- followup

Posted in ‘Admin Tools for WordPress’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

WordPress version
WordPress 6.4.2
PHP version
8.2.14 (Supports 64bit values)
Admin Tools version
Version 1.6.4

Latest post by nicholas on Sunday, 21 January 2024 14:41 CST

[email protected]

This is a followup to our ticket #40162 Security Exceptions Log question, which has been closed. This morning at 8:10am (CST - US) the update from 1.6.3 to 1.6.4 occurred as per this entry in my log:

You 8:10 am (about an hour ago) Updated plugin "Admin Tools Professional for WordPress" to 1.6.4 from 1.6.3

View changelog

However,beginning at 8:10am, my [email protected] account started receiving messages with this subject lines. As of 9:10am, we have have received 379 of these message so far.

Security exception on Denton County Master Gardener Association

or

Automatic IP blocking notification for 23.129.64.225 on Denton County Master Gardener Association

See Attachment with filename: Akeeba_SecurityExceptionEmailMessages_Screenshot1_2024-01-19.png that shows the earliest instances of the message

See Attachment with the filename: Akeeba_SecurityExceptionEmailMessages_Screenshot2_2024-01-19.png is an example of the full Security Exception message. Each of these includes a different IP address.

See Attachment with the filename: Akeeba_SecurityExceptionEmailMessages_Screenshot3_2024-01-19.png is an example of the full Automatic IP Blocking message. Each of these includes a different IP address.

We had one other instance some time ago of receiving a large number of such messages at one time. And I assuming the current event relates to the update that occurred this morning.

Any information you can provide to help us understand why this is happening, or if there is something we need to do about this will be greatly appreciated.

Thank you

Bill Moen, DCMGA Webmaster

Β 

Β 

Please look at the bottom of this page (under Support Policy Summary) for our support policy summary, containing important information regarding our working hours and our support policy. Thank you!

nicholas
Akeeba Staff
Manager

No, the plugin update is unrelated. The only thing that was changed was in the interface. It just so happens that someone is apparently running a security scanner or automated attack bot against your site at about the same time you updated the plugin.

If you do not want to receive emails about blocked requests – incidentally, I recommend that you DO NOT receive emails for blocked requests unless you're actively troubleshooting something – you can go to Admin Tools, Web Application Firewall, Configure WAF, Logging & Reporting, find the "Email this address on security exceptions" setting and empty it.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

[email protected]

Thank you!

Β 

Bill

nicholas
Akeeba Staff
Manager

You're welcome!

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!