Support

Admin Tools

#25857 Can't access joomla administrator area

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Thursday, 08 September 2016 17:20 CDT

hkeyzer
 Hi,

I'm finding this issue on a number of newly installed joomla sites with similar configurations but not all sites (on the same server):
When I access the administrator area of the site I get redirected straight to the home page of the site.
Then I disable Admintools - by renaming main.php in the plugins/admintools/admintools folder, and then try again I can access Joomla administration again.

"Allow administrator access only to IPs in Whitelist" is set to "No"

After unsuccessful attempt there is a security exception log : "Admin Query String"
But no logs in the autoIP Blocking History.

When I again enable admintools - the issue repeats it's self, until I disable admintools.

Appreciate your help in resolving this issue.

nicholas
Akeeba Staff
Manager
You have already answered your own question by telling us that you are being blocked because of "Admin Query String". That's because you need to use the secret URL parameter you have specified in the configuration.

For the meaning of the blocking reasons please consult https://www.akeebabackup.com/documentation/admin-tools/waf-log.html#waf-log-reasons

For the feature that blocks you please see https://www.akeebabackup.com/documentation/admin-tools/web-application-firewall.html#waf-configure under "Administrator secret URL parameter":

Normally, you can access your site's administrator area using a URL similar to http://www.example.com/administrator. Potential hackers already know that and will try to access your site's administrator area the same way. From that point they can try to brute force their way in (guess your username and password) or simply use the fact that an administrator area exists to deduce that your site is running Joomla! and attack it. By entering a word here, you are required to include it as a URL parameter in order to access your administrator area. For instance, if you enter the word test here you will only be able to access your site's administrator area with a URL similar to http://www.example.com/administrator?test . All other attempts to access the administrator area will be redirected to the site's home page. If you do not wish to use this feature, leave this field blank.


Please note that this is the first option you set up in the Quick Setup Wizard page.Please do read the information on the Quick Setup Wizard page carefully! If you gloss over the setup you will get confusingly get locked out of your site since Admin Tools will do what you configured it to do, not what you thought you configured it to do (speaking from experience; I've done that myself a few times I was in a rush and got a bit more sloppy than I should).

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

hkeyzer
Awesome - Product and support !!!

Understand now and all sites sorted - no more hitting "quick setup wizard" - without looking :-)

Thanks

nicholas
Akeeba Staff
Manager
You're welcome and thank you for your kind words :)

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!