Support

Admin Tools

#25499 Automatic IP blocking of my own IP without trying to login

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Sunday, 31 July 2016 17:20 CDT

Martin511
 Hello.
My own IP has been automatically blocked due to Admin Query String.
But I personally have not logged or tried to log into the site and nobody else with my IP has access to the site.

So I´m asking myself: if it was not me personally, who or what else could have made Admin Query String which ended in automatic blocking?

What can i do to avoid getting blocked in the future? My IP is dynamic, so I can´t set it into the whitelist.

Any ideas how this could have happened?

Best regards

Martin

dlb
Martin,

The thumbnail screenshots that some browsers display can cause a phantom login attempt. This is especially true if you use the secret admin parameter since the browser only uses the URL and without the secret parameter it counts as a failed attempt.

You can set Admin Tools up to email you on a failed login attempt, that would tell you when the failed attempt occurred and may lead you to what is doing it.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Martin511
Hello Dale,

yes, the site has a secret admin parameter set.
I also have set the e-mail notification and I have seen them. I just didn´t recognize that it was my own IP that has made admin query strings and was blocked due to that.

I am 100% sure that at the time this occured I did not klick any screenhots of this website or even logged in. Nothing. Nobody else was able to do this with my IP at that time.
So how can this happen? I am still confused.

nicholas
Akeeba Staff
Manager
How sure are you that this is indeed your own IP address? Is the same as what you see when you visit http://ip4.me/

If it's not the same, log in to your site and go to Components, Admin Tools, Web Application Firewall, Configure WAF. Under Basic Protection Features set Enable IP workarounds to Yes, then click on Save & Close. Read the documentation page to understand why this may be necessary on your server.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Martin511
Hello Nicholas,

yes, it is the same IP adress. Ich have checked that also yesterday to be sure it is my own IP.

IP workaround ist set to "No" - that is what was recommended by admin tools.
So I think i should not touch it.

dlb
Please change the setting to Yes. The detection for that setting is not 100% accurate. You may be one of the rare cases where the recommendation is wrong.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Martin511
Hello Dale,

ok, I´ll just wait and see if it happens once again.
If so, I will change the setting to Yes.

I only tried to understand what has happened, but I have no idea yet.

Next time I will check if the page is only blocked for me/my IP or everybody before I clean the auto IP blocking log. I missed that yesterday.

So I will wait and see and come back to you if it really happens again.

Thanks until now.

dlb
Please let me know when you find out if that fixed it. Have a good weekend!


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!