Support

Admin Tools

#9857 missing help file - and waf alert..

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Thursday, 28 April 2011 02:39 CDT

user36688
Hello,

Looking into a waf csrf alert, to see if it is legitimate or not.. I go into the documentation at this address (from the doc link for the page) https://www.akeebabackup.com/web-application-firewall --- and it appears to be a 404 page...

when looking at the exploit attempt the only info given is that it is a csrf attempt on http://domainname/index2.php

is there any other information logged on the attempt anywhere that is available to be viewed from within the atpro component?

I'm just trying to make sure that it is not a false alarm and that something should be whitelisted instead.

So far I haven't received a specific complaint from anyone on it, but want to just make sure weather it should be blocked or not.

Can you please advise?

Thanks.

H.W.

user36688
BTW.. the logout button on the forum does not appear to be functional with firefox or chrome.

HW

slaes
for the documentation you can try

https://www.akeebabackup.com/documentation/admin-tools/web-application-firewall.html

nicholas
Akeeba Staff
Manager
If you have enabled logging in WAF configuration you can review the details of the blocked request in two places: Admin Tools, Web Application Configuration, Exceptions Log and by taking a look inside your site's logs directory (the info is more detailed in there).

I think that you just have to disable the CSRFShield feature in Admin Tools' WAF Configuration, as it performs HTTP referer filtering.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!