Support

Admin Tools

#27133 security exception (login failure) despite of secret URL param.

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Thursday, 16 March 2017 18:17 CDT

victorwooten
 Hello,

I am using the secret URL parameter for Joomla backend login.
Now I noticed several security exceptions with login failure. I think a bot who tried to login.
I am wondering why the bot reached the login form.
Does this mean the Secret URL parameter is known for the bot? I think while using the Secret URL parameter it shouldn't be possible to try to login?!

It's difficult for me to explain in English I hope you understand what I mean!?

Thanks

dlb
It is very unlikely that the bot knows your secret URL parameter. The error has to do with which part gets the information first. In this case, Joomla! processes the user and password and rejects it before Admin Tools has a chance to check the secret URL parameter. The bot most likely tried to call the admin login screen directly, it didn't use the redirect from index.php. If the bot had been able to guess the correct user ID and password and gotten past Joomla!, then Admin Tools would have jumped in and blocked it for lack of the secret URL parameter.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

victorwooten
ok, thanks.
so there is no problem!?

its a "normal" attack and its blocked in a normal behaviour!?

thanks.

dlb
Yes this is a "normal" attack that has been blocked by Joomla! and Admin Tools. Nothing to be concerned about. You can't stop them from trying, you can only stop them from succeeding.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

victorwooten
ok thanks for your help :-)

dlb
You're welcome!


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!