Support

Admin Tools

#10199 Constatly blocking my IP on Sign-in, but Signed in after deleted from _ipautoban

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by Randy Prue on Friday, 06 January 2012 20:51 CST

user54516
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? Yes
Have I searched the forum before posting? Yes
Have I read the documentation before posting (which pages?)? All Admin Tools Pro Setup
Joomla! version: 1.5.25
PHP version: (unknown)
MySQL version: 5.1.53-log
Host: Dreamhost
Admin Tools version: 2.1.14


Description of my issue:

Hello, I've recently installed Admin Tools and it continues to block whatever IP i'm working at. To work I have to keep my database open and constantly delete my IP from the _ipautoban . I have a hidden login setup, and if I sign in it blocks my IP. I go delete my IP from the database and go back and I'm signed in. Then if I go to Admin Professional and sign in that section, it will sign me in but then block my IP. I delete my IP and go back and I'm in. I'm sure I have a setting wrong, but I've gone through and can't see why it's marking me as a threat by signing in. I have a hidden login, so I do have treat failed logins as security excepts set to NO. I also have Admin IPs only in Whitelist NO.

I'm getting hit constantly from someone Scranton, PA so I'm hesitant to take down the Admin Tools. Any suggestions? thanks for your help.

user54516
After changing the Configure WAF and clicking Save it kicked me out and blocked my IP.

user54516
It seems to fix the problem if I turn off the Secret URL Parameter, but I would really like to hide my login since it's getting hammered. I followed the simple renaming limitations it mentions during setup (example ab12). Any suggestions or is there another way to hide this login? Thanks for your help.

nicholas
Akeeba Staff
Manager
In order to stop Admin Tools from blocking you, you have to delete two things:
1. Your IP address from the "Automatic IP Blocking Administration"
2. All records referencing your IP from the "Security Exceptions Log"
You have to do that before re-activating the plugin. Please take a look at the troubleshooting instructions: https://www.akeebabackup.com/troubleshooter/atwafissues.html

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user54516
Thanks for your time Nicholas. I thought I was deleting my IP exceptions at the top of the list, but didn't realize they were mixed throughout pages of hack attempts. I searched for my IP address at the top and was able to delete them all. Things seem to be working now. Thanks again.

Quick question though, I feel like I'm building a wall here that's constantly getting pounded on by the same hackers from a specific city (Scranton, PA). Is there a recommended way to report them or take some kind of offense against them? It seems like sooner or later they'll get in if they're trying constantly.

Randy Prue
wad3brown (and Nicholas and anyone else who is interested). The Pennsylvania (Scranton and other cities and some New Jersey locations) attackers attempt SQL injection, occasionally RFI, and also occasionally attempt direct access to components that I do not have installed.

This leads me to believe that the attacks are scripted. Also, the direct component attempt is to /component/ not /components/ (Joomla does not install a directory called "component".

On the projecthoneypot site, many of the IP addresses and ranges are being reported as initiating these attempts. I am now blocking entire ranges.

I expect that a US citizen caught doing this would suffer severe consequences, so I suspect that the servers have been taken over from offshore.

Oh, and by the way, on two of six sites, when I go to Admin Tools > WAF > Blacklist, I am "thrown out" of the back end. I find myself in the front end of the site.

I have removed my IP address from the exceptions, and from the autoban, and I have added it to the white list.

This began to happen after:

* I restarted Chrome.
* I logged into all six sites for blacklist management (today's attacks from Pennsylvania).

nicholas
Akeeba Staff
Manager
That makes sense now :)

Regarding your question, I really like comparing to building a wall. I will now ask you this: if you had a 1 foot thick reinforced concrete wall, would you be bothered by someone pounding on it with rocks? He could try day and night for months and the wall would still stand there. That's what the attacker is doing. See this: https://www.akeebabackup.com/support/forum/admin-tools-support/hacking-attempts.html

Regarding reporting someone, your best bet is to use the ip-lookup.net service to find out who owns the IP (logically, their ISP), find their phone (yellow pages, their site, ...) and report the offender. They may require evidence. In this case, consult your host for the proper way to get Apache access logs showing all access attempts from the offending IP addresses.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

nicholas
Akeeba Staff
Manager
Randy, I just your message. The /component/ thing is part of SEF URLs when you don't have a SEF component installed.

Regarding your issue, have you updated to 2.2.a1? If so, you'll need to update to the latest dev release or wait for me to launch a new alpha.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user54516
Ha! Well true, when you put it like that it does put me more at ease. The site does seem extremely secure now and as long as I can keep my plugins updated it should be fine. Thanks again, Admin Tools is a necessity for my sites from now on. We'll be updating to the full backup system soon as well.

user54516
Randy, I'm getting the same attempts on components I don't have installed. Good to know I'm not the only one this is happening to and this is getting attention. Thanks for the info.

Randy Prue
Hi. Sorry, I have had a lot of work to do. I am using 2.1.14 until I can get a stable release of 2.2.

I will go now to read the article that Nicholas pointed to. I am fascinated by all this.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!