Support

Admin Tools

#10006 Is this an Admin Tools issue?

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Monday, 22 August 2011 13:44 CDT

user43666
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? Yes
Have I searched the forum before posting? Yes
Have I read the documentation before posting (which pages?)? Yes
Joomla! version: 1.7
PHP version: (unknown)
MySQL version: (unknown)
Host: Rochen
Admin Tools version: Latest Pro Version


Description of my issue:
Is this an Admin Tools issue? I am getting this error:
"Not Acceptable



An appropriate representation of the requested resource /administrator/index.php could not be found on this server.



Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request."

nicholas
Akeeba Staff
Manager
Nope. That's an HTTP 406 error which means that your server doesn't like what you try to pass in the URL or the POST data. Please contact your host and ask them which mod_security rule is triggered when you get this error. The usual causes are complex passwords (including characters you get by SHIFT-pressing numbers) or use fo words commonly used by spammers, like some very well known prescription medicines' brand names.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user43666
Thanks I'll contact Rochen.

nicholas
Akeeba Staff
Manager
If it's Rochen, I think I am spot on. I am also hosted on Rochen and have the exact same issues with complex passwords. A few months ago I contacted Rochen and we confirmed that it was due to Apache mod_security rules. The solution is rather simple: use non-complex passwords :)

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user43666
I changed my passwords and did not use a character but I still get the error. You seem to be more knowledgeable than the Rochen tech.
Hopefully they come up with a solution. I'll let you know.

nicholas
Akeeba Staff
Manager
Did you use any other words which may be black-listed due to spam concerns?

You can also tell Rochen's techs to take a look at the server error log. In there there will be a message which will tell them which mod_security rule was triggered when this error occurred.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user43666
I do not have any spam words black-listed yet.

I let the techs know to look at the sever error log. There still scratching their heads.

nicholas
Akeeba Staff
Manager
Please note that I am not talking about Admin Tools' black-list, but the (not editable by you) server-wide black list.

If all else fails, just send me a PM with Super Admin access to your site and tell me the exact steps I can follow to replicate this issue. This will help me understand what's going on.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user43666
I tried to make you a Super Admin user but got this message: 403 - An error has occurred. Access Denied

I will send PM you my admin login.

nicholas
Akeeba Staff
Manager
Maybe this helps: https://www.akeebabackup.com/documentation/troubleshooter/atspecialusers.html ;)

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user43666
From Rochen: You have an extension installed that's putting a string in your cookies ("8=8") that matches common a SQL Injection attack signature. This rule has been disabled now, thank you.

Is is the best policy for Rochen to just disable that rule or have the component maker change his code?

nicholas
Akeeba Staff
Manager
Yes, that makes sense. Not all rules are overly important. The specific attack that this rule is designed to block is something which has to do with cookie spoofing and vulnerable scripts. Given that all cookies go through Joomla! (which doesn't have that vulnerability) it does make sense for Rochen to turn off this rule on your site.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user43666
Thank you once again for your help.
Disregard my PM.

nicholas
Akeeba Staff
Manager
You're welcome!

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!