Support

Admin Tools

#16822 security exeption "templ= " in URL

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Monday, 22 July 2013 09:23 CDT

paulK
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? yes
Have I searched the tickets before posting? yes
Have I read the documentation before posting (which pages?)? yes
Joomla! version: (unknown)2.5.12
PHP version: (unknown)
MySQL version: (unknown)
Host: (optional, but it helps us help you)Apache
Admin Tools version: (unknown)latest

Description of my issue:
Hy,
I keep getting these "templ= in URL" exeptions for both my sites. I put the related IPs on the black list, using admin tools, each time I receive such a message. I have implemented the .htpassword for both sites, and a restrictive .htaccess file.
1- is it sufficient ? (My template is correctly identified in the URL). Should I delete the "mail to" icon from my pages ? Delete the mail to component ?
2- What is the crawler trying to do ? Should I worry ? Could they be legitimate ?
3- On one of my two sites, I keep getting the security exeption mails from the site, but when I login in the backend I found no corresponding entry in the security exeptions log of the firewall. Any idea why ?

Thanks for your tools and your support.

And by the way the troubleshooting guidelines are extremely usefull in most unexpected situations. ( I locked myself out of my site after a reset of my router, because I misunderstood the use of the IP white list...)

Regards, Paul

nicholas
Akeeba Staff
Manager
If you are talking about template= in URLs you need to enable "Allow site templates". See our documentation https://www.akeebabackup.com/documentation/admin-tools/web-application-firewall.html#waf-configure

If you are talking about tmpl= in URLs then you need to do nothing. Actually this should not even work on modern versions of Joomla! any more.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

paulK
We would like to notify you that a security exception was detected on your site, association de la plage et de la falaise de Leucate, with the following details:



IP Address: 66.249.72.69 (IP Lookup: http://ip-lookup.net/index.php?ip=66.249.72.69)

Reason: template= in URL



If this kind of security exception repeats itself, please log in to your site's back-end and add this IP address to your Admin Tools's Web Application Firewall feature in order to completely block the misbehaving user.


It is indeed template= in URL. But if I understand the documentation, by enabling "allow site templates", I will authorize those accesses instead of blocking them. Why would I do that ? I am not using multiple templates and there should be no legitimate reason for these requests...

nicholas
Akeeba Staff
Manager
As we've written in the documentation, this is how the core com_mailto component (which powers the Send by Email feature in Joomla!) works. You can either enabled the allow site templates feature or you can disable the send by email feature.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!