#13743 – Double IP-adresses in Security Exception Log warnings

Posted in ‘Akeeba Admin Tools for Joomla!’
This is a public ticket. Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.
Monday, 08 October 2012 13:01 CDT
user41123
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? No
Have I searched the tickets before posting? Yes
Have I read the documentation before posting (which pages?)? No
Joomla! version: 2.5.7
PHP version: 5.3.x
MySQL version: (unknown)
Host: (optional, but it helps us help you)
Admin Tools version: 2.4.0 Pro

Description of my issue:

Hi Nicholas,

Since the last update I recieve sometimes weird Security Exception Log warnings like this:

IP Adres: 10.0.0.92, 201.36.XXX.XXX
Reason: http://ip-lookup.net/index.php?ip=10.0.0.92, 201.36.159.201

And after an automatic block after three attemps the IP adres '0.0.0.0' is blocked. Obviously the WAF can't handle this combination of two IP-adresses?

How is it possible that two IP-adresses try "illegal actions" at the same time? In most cases the actions try to login into the website with target URL's like these: http://website.com/user/login/index.php or http://website.com/wp-login.php.
Off course these attemps are useless and will never work.

I've never seen this behaviour before in my logs. Any idea?

Greetings, Paul
Tuesday, 09 October 2012 04:38 CDT
nicholas
I think this is a bug / feature of the web server or proxy software you are using. The 10.0.0.x addresses belong to the IP private address space, not used in public networks (see RFC 1918, §3). It's the first time I've seen that, but it seems that it's not uncommon.

I just made a modification in Admin Tools to catch those cases. You can find it in the latest dev release. Please install and verify the fix as I can't reproduce this on my testing servers. Thank you in advance!


Nicholas K. Dionysopoulos

Lead Developer and Director



🇬🇷Greek: native

🇬🇧English: excellent

🇫🇷French: basic



Please keep in mind my timezone and cultural differences when reading my replies. Thank you!



Tuesday, 09 October 2012 10:24 CDT
user41123
Hi Nicholas,

I just installed the DEV-release and will let you know the results a.s.a.p.

Have a save trip back.

Greetings, Paul
Tuesday, 09 October 2012 11:54 CDT
nicholas
All right! Let me know how it works.


Nicholas K. Dionysopoulos

Lead Developer and Director



🇬🇷Greek: native

🇬🇧English: excellent

🇫🇷French: basic



Please keep in mind my timezone and cultural differences when reading my replies. Thank you!



Wednesday, 10 October 2012 12:59 CDT
user41123
Hi Nicholas,

Since I installed the DEV release no more double IP-adresses are logged in the Security Exception List so I suppose you fixed this issue.

Thanks for your support!

Greetings, Paul
Wednesday, 10 October 2012 13:06 CDT
nicholas
Great! Thank you for the feedback :)


Nicholas K. Dionysopoulos

Lead Developer and Director



🇬🇷Greek: native

🇬🇧English: excellent

🇫🇷French: basic



Please keep in mind my timezone and cultural differences when reading my replies. Thank you!



This ticket is closed, therefore read-only. You can no longer reply to it. If you need to provide more information, please open a new ticket and mention this ticket's number.

Support Information

Working hours: Typically we work Monday to Friday, 9am to 7pm Cyprus timezone (EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets, but we cannot respond to them, outside of our working hours.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!