Support

Admin Tools

#26431 A user successfully signed up to the site using IP address as User Group: Administrator

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Friday, 02 December 2016 17:17 CST

thongdoan
 Hi Nicholas,
I got this email

"Hello administrator,
A new user 'updater', username 'updater', has registered at http://mywebsite.ca/."

I think I am having problems because a user successfully signed up to the site using IP address as User Group: Administrator

Name*: updater
Login Name*: updater
User Group: Administrator
Email*: [email protected]
Last Visit Date: Never

User Notes: Sign-up IP address

The user signed up to the site using IP address 173.208.211.250

The user agent string of the user's browser was:
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:49.0) Gecko/20100101 Firefox/49.0

This information was automatically recorded in this User Note by Admin Tools Professional.
but it's not shown in Security Exceptions Log



My website:
Joomla! 3.6.2
PHP 5.3.28 (my hosting provider can not upgrade PHP to a higher version so I am using Admin Tools Professional 3.8.3)

My Admin Tools: Configure WAF is as the following:

Enable IP workarounds: NO
Allow administrator access only to IPs in Whitelist: NO
Allow administrator access only to IPs in Whitelist: YES
Administrator secret URL parameter: XXXXXXXXX

IP blocking of repeat offenders: YES
IP blacklisting of persistent offenders: YES
Permanently blacklist IP after: 3 automatic IP blocks

I wonder how can a user successfully signed up to the site using IP address as User Group: Administrator without loggin and how to prevent this happenning again? Please help.

Thank you very much.

dlb
This is a Joomla! bug that was revealed (and a fix issued) last week. The version of Admin Tools released at the same time, 4.0.2, will block this bug, but your version is still vulnerable. You need to update Joomla! and/or Admin Tools immediately.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

thongdoan
Thank you Dale!

dlb
You're welcome!


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!