Support

Admin Tools

#18671 Our site was compromised

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by dlb on Friday, 03 January 2014 08:52 CST

thexmannz
 Hi there, despite running Admin Tools Pro, our site was compromised late last year via the weblinks folder. I have been told that the Apache logs show numerous attempts from hackers to access the site etc. I have been running the .htaccess maker but despite all this, the admin tools shows exactly zero security exceptions, for the entire year. How can this be ?

dlb
Please make sure the security log is enabled. Go to Admin Tools, Web Application Firewall, Configure WAF, in the Logging And Reporting section, make sure Log security exceptions is set to Yes.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

thexmannz
I have another site with absolutely zero exceptions and BOTH instances the Logging in the Config is set to YES.

dlb
Actually, that would be correct. The .htaccess Maker would set up security at the Apache level, any exceptions from .htaccess would be in the Apache error log. Security exceptions from the Web Application Firewall would hit the Admin Tools Security Log.

It seems very strange though that your security log is empty. I have a hacker whose goal in life appears to be to log in to my site as administrator. I have the Administrator secret URL parameter set up and get hundreds of exceptions from that defense alone. I would recommend that you take a look at the WAF and see what portions are enabled and what sort of security exceptions you would expect to get from that.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!