Support

Admin Tools

#16431 Secret URL

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by allright on Monday, 17 June 2013 10:51 CDT

allright
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? yes
Have I searched the tickets before posting? yes
Have I read the documentation before posting (which pages?)? yes, WAF configuration
Joomla! version: 2.5.11
PHP version: 5.3
MySQL version: (unknown)
Host: siteground
Admin Tools version: 2.5.5

Description of my issue: I assigned a secret url for admin login, however I still get reports of Login Failure with the usual user name and password. How can someone login if they don't have the secret url?, or did they make a lucky guess?

thanks

nicholas
Akeeba Staff
Manager
This is an artefact caused by the way Joomla! fires plugin events and the plugin events each feature of Admin Tools needs to hook on. In so many words, the login failure detection code runs before the secret word code. Even if the attacker would guess the login username and password correctly they would still get redirected to the site's front-end home page, without any sign that they were able to log in correctly.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

allright
that explains it, thanks much

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!