Support

Admin Tools

#20314 Feat. request: Blacklist IP inmediately as soon as a specific exception is being detected

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by user9198 on Wednesday, 18 June 2014 10:49 CDT

user9198
 Hi Nicholas,

I'll try to explain with details why I'm asking you the Ref. new feature:

SCENARIO:
- I have already enabled the WAF 'admin directory' and 'secret parameter'
- The most often exceptions reports I'm daily receiving are 'Admin Directory' resulting till up to 4 email warnings by IP each time... A lot!
- The 90% of those 'Admin Directory' (correctly filtered by ATPro) exception attempts arrived from Turkey and IP range from IP 78.160.1.1 to IP 78.191.255.255 owned by ISP: Turk Telekomunikasyon Anonim Sirketi (AS9121).
- As you surely know, to GeoBlock turkey origin, don't stop the mentioned 'Admin directory' access attempts.
- Temporarily, I could IP blacklist the mentioned IP range 78.160.1.1-78.191.255.255 but that's not a good solution knowing the IP's may be changed randomly but very often.

FEATURE REQUEST:
I would like to have the option to 'mark' to have immediately blacklisted its corresponding origin IP as soon as a specific exception is being detected (the 'Admin Directory' exception under my today scenario).
Of course, this new feature rules could need to override the default WAF 'Auto-ban repeat Offenders' ones that I have set by default as 'Block after 3 attacks, in 1 minutes that are not able to block the mentioned ones but are very useful to block other exceptions.

Your comments will be always very welcome.
Hoping this feat. request could be welcome at your side, too
Rgrds,

Note: Going now to update AT to the new 3.0.2 Pro version. Thanks!

nicholas
Akeeba Staff
Manager
I am explaining this at least twice a month. No, it will not be implemented. It is a Bad Idea™. No decent hacker –or even a script kiddie– will hold on to the same IP for a long time. All you will gain with automatic permanent black listing is banning your legitimate clients and yourself every time an innocent mistake is made. You'll also end up prospective clients or innocent visitors from the IPs which formerly belonged to a wannabe hacker, even if that was months or years ago. Also, as a bonus, you'll get really crappy performance on your site. I can think of easier ways to screw your site than implementing this kind of irresponsible feature.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user9198
Thanks a lot for your time you spent to answer me.
Rgrds,

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!