Support

Admin Tools

#18043 Getting blocked IPs message when accessing somea areas of my site

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by carcam on Tuesday, 05 November 2013 04:02 CST

carcam
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? Yes
Have I searched the tickets before posting? Yes
Have I read the documentation before posting (which pages?)? Yes
Joomla! version: 2.5.14
PHP version: 5.3.26
MySQL version: 5.5.31
Host: Siteground
Admin Tools version: 2.5.6 and 2.5.8

Description of my issue:
After successful loging in my site backend I get the IP Blocked message (the one I defined in the WAF configuration) when I try to perform some actions:

  • Trying to install any extension
  • Trying to access WAF configuration
  • Trying to clean site cache from Joomla! maintenance area


To avoid this I have to rename the pro.php file.

Weird thing is that thinking it might be an accumulation of incidences from my IP (I have a dynamic ip so I'm not sure who had it before) I have:
  • Removed all the incidences of my IP from the Security Exceptions Log
  • Checked the IP is not in the Auto-ban list or in the Black list.


Also if I check the security exceptions log after getting the message I can see no entry about that exception.

I have no clue about this problem and I think it might be related with hosting, but I also think it's weird not having a log entry about the exception.

Thank you very much.

dlb
Are you logging in with an Administrator or Super Administrator ID? Some parts of Admin Tools - like installing new extensions - require Super Administrator level access by default.

Dale


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

carcam
Hi Dale,
thank you very much for your reply.

I'm logged in as Super Administrator. Also that does not cover the issue with cleaning cache.

dlb
That was the only thing I could think of that you hadn't already looked at. I'll ask Nicholas to take a look at this.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

carcam
No problem Dale, much appreciated your help ;)

I'm not in a rush with this I just want to be sure this is not a bug or an incompatibility we have not considered ;)

Best!!

nicholas
Akeeba Staff
Manager
Hi Carlos,

Admin Tools does not apply its security checks in the back-end. As a result it can't block your IP. The only way this can happen is if your session expires and you try to repeatedly (e.g. due to a bad redirection) access the login page without providing the secret URL parameter.

Another possibility is that you have a misconfigured server which reports the same IP (typically that of a reverse proxy or a CDN in front of the site) instead of the real visitor's IP. In this case other users triggering the WAF in the front-end would result the –always the same for everyone– IP to be blocked very fast, leading to the issue you are reporting.

The only way to know what's going on is to wait for it to happen again. Then record the reason shown next to your IP in the Administer Auto-block IP page. It would also help if you could then look up that reason and that IP address in the Security Exceptions Log and paste me the Target URL.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

carcam
Hi Nicholas,
thank you very much for your reply. As I wrote in my previous message the behavior was perfectly reproducible:


when I try to perform some actions:



Trying to install any extension

Trying to access WAF configuration

Trying to clean site cache from Joomla! maintenance area



And also as I stated:

Also if I check the security exceptions log after getting the message I can see no entry about that exception.


So I have not been able to find a reason for that weird behavior.

I say "was" because I have tried to reproduce the issue again and now everything is working as it should, so I guess there is no issue. I can only guess this:

Another possibility is that you have a misconfigured server which reports the same IP (typically that of a reverse proxy or a CDN in front of the site) instead of the real visitor's IP. In this case other users triggering the WAF in the front-end would result the –always the same for everyone– IP to be blocked very fast, leading to the issue you are reporting.


was the main reason as Siteground uses that SuperCacher thing but it was quite weird as it only happened with specific functions of the backend and not with each backend step I took and I got no log in the Security exceptions log.

I'll let you know if I can find more info or if it happens again.

Thank you very much for your clarifications and I'm sorry for not being able to provide more data.

nicholas
Akeeba Staff
Manager
You can at least help me by providing something easy to determine: does the blocked IP appear in the automatic IP blocking page? If so, what is the reason listed next to it?

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

carcam
Hi Nicholas,
sorry I thought I already mentioned that. There was only one IP in the automatic block, the reason was adminpw and it was not my IP. It was a USA IP and our server should be located in Europe.

PS: Shouldn't you be sleeping at this time? :P

carcam
This is the site IP info:

http://ip-lookup.net/index.php?ip=107.6.161.202

It looks to me like a Siteground IP so it seems your CDN guess is the most probable reason.

Thank you very much for helping me shedding some light on this.

nicholas
Akeeba Staff
Manager
Yup, that's exactly the problem. You have most likely enabled CloudFlare CDN through SiteGround's control panel, but for some reason the X-Forwarder-For HTTP header is not set. Just make a quick call to SiteGround and they'll sort it out for you.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

carcam
Thank you very much for your help.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!