Support

Admin Tools

#17201 regarding #17191: problem posting topics on kunena

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by user74692 on Monday, 26 August 2013 03:45 CDT

user74692
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? yes
Have I searched the tickets before posting? yes
Have I read the documentation before posting (which pages?)? yes
Joomla! version: both 2.5 and 3.1
PHP version: (unknown)
MySQL version: (unknown)
Host: inmotion
Admin Tools version: (unknown)

Description of my issue:

Plus, the errors you got indicate that you have a screwed up Joomla! installation, not an Admin Tools issue.


I wasn't trying to point the finger at admin tools as the problem. I was just reporting a problem i had and the fix i found for it in the hope it may help someone else with the same issue and also help me figure out what exactly the problem was. But nobody replied to help me trouble shoot at all. It just so happened that recreating the .htaccess file and saving admin tools firewall settings finally did the trick.

I un-installed nearly every component/module/plugin except for kunena and akeeba before using admintools to upgrade the site to 3.1. Almost a completely clean install. I cant see how my joomla setup can be screwed up but since you mentioned it im now worried, can you be a little more specific.

nicholas
Akeeba Staff
Manager
The error message trail gave a fatal error in a core Joomla! file.

If the problem was related to Admin Tools you would have gotten a security exception log entry in the back-end of the component. Nothing is silently blocked.

As for the .htaccess, if something is blocked you get a 403 Forbidden error page from the server. Joomla! doesn't continue to load – which is opposite to what you reported.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user74692
Hi Nicholas
Thank you for the extra info. I will keep my eye on my install. It started as a 1.5 site so its been through a lot.

I love Akeeba

Marinos

nicholas
Akeeba Staff
Manager
You're welcome!

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user74692
Hi

Just to follow up on this

After refreshing the site the problem started again on my 2.5.14 install. I played a little more with the akeeba configure WAF settings changing them one by one and found that turning "Remote File Inclusion block (RFIShield)" off helped.

nicholas
Akeeba Staff
Manager
RFIShield means that one of your site's pages is trying to load PHP code from a remote server or at least appears to be doing so. If you also give me the Target URL as shown in the Security Exceptions Log of Admin Tools I would be able to help more.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user74692
Hi Nicholas

Nothing was showing up in the log. I have backed up my old site and can still access it. Could I give you administrator access to that instead?

nicholas
Akeeba Staff
Manager
If there is nothing showing up in Admin Tools' security exceptions log (and you have not disabled logging) then modifying any Admin Tools option won't have any effect on your site.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user74692
I just tested it again on joomla 2.5.14 and when I turn on Remote File Inclusion block (RFIShield) i get errors when trying to make a new forum post. Also when I turn errors in joomla config off I just get a blank page. On the joomla 3.1 site I don't get errors when Remote File Inclusion block (RFIShield) is set to "on" but it takes a post 30 seconds to submit, with Remote File Inclusion block (RFIShield) set to "off" the forum posts are quick. Nothing shows in the admin tools exception log.

I found this in the docs - does it mean im not to worry because "Disabling this option is such a case poses no security risk"

Remote File Inclusion block (RFIShield)

Some hackers will try to force a vulnerable extension into loading PHP code directly from their server. This is done by passing an http(s):// or ftp:// URL in their request, pointing to their malicious site. When this option is enabled, Admin Tools will look for such cases, try to fetch the remote URL and scan its contents. If it is found to contain PHP code, it will block the request.


[Important] Important

If your site starts throwing white pages when submitting a URL in your site's front-end, please disable this option. The white page means that your server is not susceptible to this kind of attack and doesn't properly advertise this to Admin Tools when requested. In this case, Admin Tools crashes while trying to scan the contents of the remote location, causing the white page error. Disabling this option is such a case poses no security risk.


apologies for the hassle

nicholas
Akeeba Staff
Manager
Please refer to my previous reply https://www.akeebabackup.com/support/admin-tools/17201-regarding-17191-problem-posting-topics-on-kunena.html#p98348

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user74692
but it does have an affect on my site. if i enable (RFIShield) my forum stops working and nothing shows in the log - this log right? --> joomla admin/components/admintools/web application firewall/security exeptions log

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!