Support

Admin Tools

#9795 What to do when it just doesn't work.

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Friday, 18 March 2011 10:31 CDT

user33310
I'm trying to get WAF of Admin Tools v2.0.1 to work but something is definitely wrong. I'm getting "This Plugin cannot be reordered" and it's set to -30000. I've disabled pretty much anything that might be interfering with it including RokGZipper, GantryCache, JHackGuard (SiteGround extension) and I've uninstalled and reinstalled Admin Tools. The Joomla instance is v.1.5.22 on a subdomain of my SiteGround account.

The expected functions of WAF Admin Tools is not working. It isn't blocking the fingerprinting items, etc. and the Security Exceptions Log is not recording anything I attempt.

The System Information from the Admin Help System Info menu is below.

Thanks for any help.

Mark
PHP Built on: Linux serv01.siteground167.com 2.6.28.5-grsec-sg2 #6 SMP Fri Feb 20 02:45:11 CST 2009 i686
Database Version: 5.0.91mm-log
Database Collation: utf8_general_ci
PHP Version: 5.2.9
Web Server: Apache/1.3.42 (Unix) mod_gzip/1.3.26.1a mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_ssl/2.8.31 OpenSSL/0.9.8e-fips-rhel5 PHP-CGI/0.9
Web Server to PHP interface: cgi
Joomla! Version: Joomla! 1.5.22 Stable [ senu takaa ama woi ] 04-November-2010 18:00 GMT
User Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2.15) Gecko/20110303 Firefox/3.6.15

nicholas
Akeeba Staff
Manager
First go to WAF Configuration and make sure that all the relevant options are enabled. Do note that unless you enable the log option, no intrusion attempt will be logged even if it's blocked! Also note that some of the protection offered by Admin Tools is not in the WAF, but in the .htaccess Maker page. Items blocked by the .htaccess generated by Admin Tools will not be logged by Admin Tools, as the request never hits Joomla! in the first page.

After doing that, go to your plugins manager and make sure that the Admin Tools plugin is indeed published (green checkmark). The default ordering (-30000) ensures that it loads first, as it should, so there's no need to reorder it.

Finally, try to trigger its protection. For example, if you have enabled the tp=1 protection you can try visiting http://www.yoursite.com?tp=1. Without WAF you should see the module position names on the page. With WAF, you should see your normal site, without the module names being spat out. If you have enabled the template=foo protection, try accessing your site as http://www.yoursite.com?template=somethinginvalid. It should block it. If this doesn't happen, please let me know.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

nicholas
Akeeba Staff
Manager
Correction: where "blocked" read "displayed with your default site template". Sorry, it's just getting late for me :)

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user33310
I am now about 99.99 percent convinced that the problem being experienced is with my host and not Akeeba nor Joomla. The WAF magically started working on its own yesterday a few hours after I made the post. Actually, it may have been sooner than that but I didn't check it again until just before going to bed.

This morning, I made a couple of minor changes to the .htaccess file (manually) and the changes are slow to take effect.

I'm ready to conclude that my host (SiteGround) is using some caching algorithm that is delaying changes from being reflected. Having said that, I am still very pleased with SiteGround. But, from now on I will do tweaks and experiments on a local server first.

Nicholas: Thank you so much for developing such awesome tools. I gladly paid the 85 euros for Professional and haven't looked back. You rock!

nicholas
Akeeba Staff
Manager
You're welcome! I am glad you got to the bottom of this :)

It seems that SiteGround does have some strange issues. Over the last two weeks I started receiving complaints about "bugs" which were actually caused by SiteGround. For starters, CRON backups running for more than 90 seconds started being aborted. Sometimes uploading backups to remote storage fails and then starts working for no apparent reason. Now we have the strange caching. All of this makes me believe that SiteGround did some changes to its server configuration that have affected the quality of the provided service :(

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user33310
My wife and I run a graphic design business in a small town. One of our many services is web site design and management. We're using SiteGround and, so far, haven't had any big issues. However, I have considered going to a dedicated server or an EC2 in the cloud.

Any feedback regarding this is appreciated.

user33310
Can the title of this thread have the word "Solved: " appended to it? Thanks.

nicholas
Akeeba Staff
Manager
EC2 is too expensive if you don't need the scalability it brings. I'd suggest opting for an MVS at Rochen, which is very fast and reliable. It's the exact kind of hosting we have on AkeebaBackup.com ;)

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!