Support

Admin Tools

#10177 Over 1,000 Attacks in 3 weeks

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Tuesday, 27 December 2011 02:47 CST

kerrynoy
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? N/A
Have I searched the forum before posting? Yes
Have I read the documentation before posting (which pages?)? N/A
Joomla! version: 1.5.25
PHP version: 5.2.17
MySQL version: 5.1.56
Host: Crucial Paradigm
Admin Tools version: 2.1.5-pro


Description of my issue:

I was not sure where to post this so if I have added it to the wrong section, I apologize in advance.

After a dozen or so sql and MAU attacks on several website running Admin tools pro I modified the notice that is shown to hackers after unsuccessful login attempts from the standard "you are a hacker etc" to a clear message of exactly what I thought of them ("hackers") with some descriptive adjectives and a direction to what cliff they could jump off.

For some unknown reason to me, this character assessment and subsequent instructions were not taken well, and as a result a number of my sites were subject to over 1,000 attacks in a matter of 2 weeks.

Fortunately all these sites were running Admin Tools professional. I ended up with over 9 pages of blocked ip addresses (and IP ranges) as a result. I was concerned that with the barrage of sql, MUA and other attempts that Admin Tools might be overwhelmed and one attempt might get through.

Admin tools performed like a 100 foot thick reinforced concrete wall. Not one got through!!!!

So, My Complements to the Chef (Dev Team) for protecting my bum. Admin Tools is one hell of a program.

In closing I would offer this one piece of advice. It is probably not a good idea to put in print to hackers what you actually think of the scum bags. However if you are running Admin Tools Pro, you may just get away with it.

Thanks for a great piece of work.

Kerry

slaes
In closing I would offer this one piece of advice. It is probably not a good idea to put in print to hackers what you actually think of the scum bags.

THUMBS UP TO THE ABOVE COMMENT

Back in the days when i was obsessed with screwing hackers back, without being too descriptive the reality is for most hacks, the hacker them self needs to leave lots open at there end to execute what they are trying to do. If you know what they are looking for and where they are looking, you dont have to be the sharpest tool in the shed to work out how to leave some very nasty surprises for them, nasty enough to put them out of business and cause major inconvenience for at least a 3-4 hours on that machine.

Great Idea, and worked very well indeed, however just know, being in the hackers yellow pages is not a good thing, as you can never sleep as well at night. Bottom line, not a good idea.

And yes Niko is the man!! ;)

nicholas
Akeeba Staff
Manager
Hi Kerry,

Even though it's not really advisable to express your deep emotions of, um, undisputed affection towards the potential crackers, I wouldn't expect this having anything to do with the attacks. We have observed a huge spike in automated attacks (hacking bots) since early November. The good news is that the hackers are using obscenely old attack vectors, targeting components which have had two dozen of updates since they were last vulnerable, Mambo (yes, I do mean Joomla!'s predecessor from early 2005!). The most "updated" attack was one launched en masse just before Christmas, targeting last year's (April 2010) phpThumb exploits, essentially targeting a very old version of FLEXIcontent which uses this library.

All those obscenely outdated attacks have nothing on WAF. It's like someone throwing lemons to thick, steel-mesh reinforced bulletproof glass. I would be honestly surprised if any of them got through :D

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!