Support

Admin Tools

#22325 Change administrator login directory to missing

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Tuesday, 24 March 2015 03:08 CDT

Burbano
I upgraded to version 3.5.0 Admin Tools and I find the surprise that the administrator login option Change directory to no longer exists. But the option still appears the box where different sets administrator word is gone and I lost that functionality on all sites I manage. I returned to the previous version, but I do not as convenient. Tell me if it is a permanent change and these changes without consultation policies are always applied. Apparently that's the case as I see in another ticket. I purchased the software for that feature, among others and in my case the change of administration directory is recent in multiple accounts. I had to send communications to multiple clients informed of the change and the benefits of new securities and now I have to reverse that communication by its decision without consultation with users, I think we deserve a better deal. I ask please that include this feature that is important part of your securities again. Hope that helps me with a solution that will better their service concept.

He actualizado a la versión 3.5.0 de Admin Tools y me encuentro con la sorpresa que la opción Change administrator login directory to ya no existe. Continúa apareciendo la opción pero el casillero donde se pone la palabra diferente a administrator ya no está y he perdido esa funcionalidad en todos los sitios que administro. He regresado a la versión anterior, pero no creo que sea lo más conveniente. Dígame si es un cambio permanente y esas políticas de cambios sin consulta se aplican siempre. Al parecer ese el caso según veo en otro ticket. Yo he adquirido el software por esa característica, entre otras y en mi caso el cambio del directorio de administración es reciente en varias cuentas. He tenido que enviar comunicaciones a varios clientes informando del cambio y de las bondades de las nuevas seguridades y ahora tendré que revertir esa comunicación por su decisión sin consulta con sus usuarios, creo que nos merecemos un mejor trato. Pido por favor que se vuelva a incluir esa característica que es parte importante de sus seguridades. Espero que me ayude con una solución que ponga en mejor concepto su servicio.

dlb
The feature has been removed. The text you see on the screen is a cosmetic error that will be fixed in the next release.

A discussion of why the feature was removed was in the Release Notes for the update. It did not work consistently on all servers. We were not able to even predict which servers the feature would work with. If Nicholas can figure out how to make it work on all (or almost all) servers, he will consider returning it to Admin Tools.

The feature did not provide any protection for your admin login, it obscured the location of the login form. You can provide the same function with the Administrator secret URL parameter. If you password protect the administrator folder, you provide actual server-level protection for your administrator folder.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Burbano
It seems that knows the trouble I caused. Now published the discussion by malfunction as I'm not up to me. On my server it worked perfectly and never informed me it was a beta feature that could be withdrawn. So I used it, relying on their seriousness, I see that I was wrong. What they should do is reinstate publishing its compatibility warning does not affect me at all. In debian wheezy and jessie php 3.4 and 3.6 with apache 2.2 and 2.4 works. I do not know about what kind of servers will not work and is not of interest to me, but it works for me and not think that my server is so weird. I hope that a solution could be even tell me how to program internal redirect with these features with Apache 2.4. I repeat that again change the form of income causes me severe discomfort in a production server, I have not a test server! Your software ever imagined that was proof!

Parece que no conoce las molestias que me ha causado. Ahora publican la discusión por funcionamiento incorrecto que a mí no me compete. En mi servidor funcionó perfectamente y jamás se me informó que era una característica beta que podría ser retirada. Por eso la usé, confiando en su seriedad, veo que me he equivocado. Lo que deberían hacer es reincorporarla publicando su advertencia de compatibilidad que no me afecta en lo absoluto. En debian wheezy y jessie con php 3.4 y 3.6 apache 2.2 y 2.4 funciona. No sé sobre que tipo de servidores no funcionará y no es de mi interés, pero a mí me funciona y no creo que el mi servidor sea tan raro. Espero que me de una solución que podría consistir incluso en decirme por interno la forma de programar una redirección con esas características con apache 2.4. Reitero que volver a cambiar la forma de ingreso me provoca graves molestias en un servidor de producción, yo no tengo un servidor de pruebas! Ysu software jamás me imagine que era de pruebas!

Burbano

His assertion that provides no protection feature is incorrect. I managed to lose that way brute force 200 a day to nearly 0. Put another password to access the administration seems to me too. In any case this should be a user deisción mo of you!

Su afirmación de que no proporciona ninguna protección la característica es incorrecta. Logré bajar de esa forma ataques de fuerza bruta de 200 al día a casi 0. Poner otra contraseña de acceso a la administración me parece demasiado. En todo caso esa debe ser una deisción del usuario mo de ustedes!

Burbano
What assures me that the other features will not be removed?

¿Qué me asegura que las otras características no serán retiradas?

nicholas
Akeeba Staff
Manager
The fact that the other features actually DO work and HAVE worked for the longest time is assurance enough that they won't be removed.

In any case, the administrator directory feature will be added back but WITHOUT ANY SUPPORT and a big banner that if you enable it you are not going to receive support. That's the trade-off you'll have to make.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Burbano
Thank you for your Nicolas solution, I still think that warning should be included before to avoid the inconvenience this time, I never thought that as robust as designed software for you would be removed as important as that of a point feature to another. Admin professional tools I acquired less than a year ago and that feature was always present, unaware that they had built recently and had problems, nobody told me and I did not need to know, I'm finding out now. To me it has worked well for two months that I decided to include it on all the sites I manage, advising all my clients do, I hope you continue to perform well when rejoin the option with the warning that take now that I have already incorporated the option perhaps he had not previously being warned in time. I used Akeeba Backup for years and always found a mature software, just once I asked earlier by the software support that always seemed very stable. This really was not a request for support for software malfunction or poor configuration mine was a claim for a policy that I think does not account for serious users in production environments who appreciate the quality of their software. If the rectified and tells me appreciate and wait for the new version to update to the 3.5.x branch, I hope somehow be warned that this version has that feature and hope not to have to spend too much time with a version of its software outdated. My language is Spanish and this is a google translation. Below the original.

Fabián Burbano

Gracias por su solución Nicolás, sigo pensando que esa advertencia debió estar incluida antes para evitar el inconveniente este momento, yo jamás pensé que a un software tan robusto como el diseñado por usted le quitarían una característica tan importante como esa de un momento a otro. Admin tools profesional lo adquirí hace menos de un año y esa característica siempre estuvo presente, desconocía que la habían incorporado recién y que tenía problemas, nadie me lo dijo y yo no tenía por qué saberlo, me estoy enterando este momento. A mí me ha funcionado bien desde hace dos meses que me decidí por incluirla en todos los sitios que administro, avisando a todos mis clientes, espero que siga funcionando así cuando reincorporen la opción con esa advertencia que la tomaré ahora que ya he incorporado la opción, tal vez antes no lo hubiera hecho de ser advertido a tiempo. He utilizado Akeeba Backup por años y siempre me pareció un software maduro, apenas una vez pedí soporte anteriormente por ese software que siempre me pareció muy estable. Este en realidad no fue un pedido de soporte por mal funcionamiento de software o por mala configuración mía, fue un reclamo por una política que me parece no toma en cuenta a usuarios serios en entornos de producción que aprecian la calidad de su software. Si la rectifican como me dice lo apreciaré y esperaré a la nueva versión para actualizar a la rama 3.5.x, espero ser avisado de alguna forma de que esa nueva versión incluye esa característica y espero no tener que pasar demasiado tiempo con una versión de su software desactualizada. Mi idioma es el español y esta es una traducción de google. Abajo el original.

Fabián Burbano

nicholas
Akeeba Staff
Manager
Um, that feature was added about six months ago. It was not "always there". It is also not an important feature. It does NOT add any security. It is still easy to circumvent by someone who knows what they are doing. Even worse it doesn't actually rename the directory itself (it is impossible without breaking Joomla! and all third party extensions), it only abuses Joomla!'s SEF URL handling to make you think that the administrator directory is renamed. This requires overriding SEF extensions, setting cookies and performing redirections. All of these are 90% voodoo. Will they work? Maybe. Can they be made to always work? When Hell freezes over.

So all I did was suspend a crappy feature with no security impact. The last time I did that was with GeoBlock. The same story played out. People who don't know better demand the feature back even though I explain that no, this feature is NOT a real security feature and here's your better alternatives which really do add security to your site. I get it. You don't care about the actual security features which are out of sight and out of mind. You want the fanfare, even though it does pretty much nothing to secure your site. All right, all right, keep your fanfare, sheesh!

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!