Support

Admin Tools

#19207 Persistent AdminQueryString attack advice please

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Monday, 17 February 2014 15:50 CST

supergran
 Hi
First, thank-you for a great product which has earned its keep this weekend alone!
My question is not with a problem with your admin tools product, far from it, but with needing some further advice with what to do after an attack I have read some of your articles oponted to where others have written to you and learned a bit more about the tool and Joomla itself, most notably the emergency off line feature compared with the Joomla feature. A great tool and explanation.

This weekend I started to get hit with numerous AdminQuery String security exceptions, about 7 a minute. My email inbox went into overdrive. I am using the super administrator ID. I had enabled auto IP blocking after 3 attempts but, or course the ip addresses purported to come from many countries and are likely spoofed.I used the emergency off line feature and took the site down for a few hours, I also changed the admin username and password as a precaution. In all there were over 1100 attempts before I got the site down.
I've now put it back up but noticed more measured attempts. Instead of a battering of tries there are now 3 attempts from an IP address minutes or a couple of hours apart. After using the same address 3 times the ip changes.
My question is really one of advice, is there anything I should do after doing the look up of an ip address? Usually the domain name isn't available although on occasion it is. Should I be doing something once I look these things up? I have enabled the project Honeypot feature. Also can you tell me what settings you recommend in this situation in terms of how many times per hour / day / week to set for IP blocking and for what duration you recommend? At one point before I took the site down I blocked all countries except the UK to calm i down but the site does cater for overseas visitors so that's not really practical.
I'm no expert as you can tell but I suppose the plus side of this weekend is that I'm learning more about the benefit of Admin Tools and also about Joomla itself as I read your articles.
Again, thank you for any further advice.

nicholas
Akeeba Staff
Manager
The best protection is to not let attackers run Joomla! at all, therefore making it impossible to log in to the administrator and save yourself from all the emails. It is surprisingly trivial to do (I have done that on our site because of the same reasons as yours): enable the Administrator Password Protection. Since the attackers will not know this extra username and password your web server (Apache) will block them from accessing administrator, long before Joomla! and Admin Tools execute. Try it, you'll be pleasantly surprised by the results.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

supergran
Thank you Nicholas!
For some reason I was nervous about using that because of the comments about some hosts and 1and1 has been a little quirky albeit that I can usually work around the issues eventually. I've now done that and so far so good :)
Thank you for the quick response.

nicholas
Akeeba Staff
Manager
You're welcome!

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!