Support

Admin Tools

#16786 AdminTools is not blocking SQL injections

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Wednesday, 17 July 2013 12:05 CDT

user75958
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? Yes
Have I searched the tickets before posting? Yes
Have I read the documentation before posting (which pages?)? Yes
Joomla! version: 2.5.11
PHP version: 5.5.0
MySQL version: 5.5.32
Host: Apache 2.2.3 CentOS
Admin Tools version: 2.5.5 professional

Description of my issue:
We've been trying any possible way of shielding our sites from SQL injections, and that's why we purchased AdminTools. I read the manual, created a .htaccess file, set the SQLiShield on, and other options, but we're still vulnerable. We've always tried with the simple parameter "?a=select a from b" after our urls to verify it, and they are still accesible. What else could we do to be really shielded? Is it an admintools problem? The server is ours, but we started working with apache very recently, and we don't know where we could change settings to help admintools to make its work. Any help would be great.

nicholas
Akeeba Staff
Manager
That's not an SQL injection, that's why. An SQL injection suffixes dummy data with a union query or a semicolon and the malicious query. Any software that would allow what you wrote here to result in this query being executed should be banned from the Internet as it means that it accepts arbitrary, unsanitated SQL queries. This kind of components cannot be protected. Ever.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!