Support

Admin Tools

#29866 login is blocked now

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Thursday, 26 July 2018 17:17 CDT

pk@klinke,de
Today I was working inside the backend of a joomla site.

Suddenly I was logged out and the message "Login is blocked now!" occured. Same I already had last week.
Now the frontend and backend are blocked with this message.

What's happened and what's the reason for this?

Peter

Β 

Sincerely

Peter

nicholas
Akeeba Staff
Manager
There is no such message in Admin Tools. Are you using another third party security plugin or a web application firewall external to your site?

If the message is something you have entered in Admin Tools to display when blocking an IP address please let me know. My answer will be completely different in this case.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

pk@klinke,de
Hi,

thank you for quick response.

I now found the string inside admintools, please see attachment.
Sorry, it is in German language.

Additionally the admin received an security exception reason: 'admin query string'

Regards
Peter

Β 

Sincerely

Peter

nicholas
Akeeba Staff
Manager
OK, that makes more sense and it's easy to understand.

You have enabled the Administrator Secret URL Parameter feature in the Web Application Firewall.

While you were working on your site's backend you stayed on the same page for an amount of time longer than what you have configured as the Session Lifetime in your site's Global Configuration. This means that your session expired. Therefore you are practically logged out at this point.

The very next thing you tried to do was to save something or navigate to another backend page. However, since your session expired you were logged out. Therefore you are trying to access an administrator page without being logged in and without providing the Administrator Secret URL Parameter. This causes a security exception in Admin Tools.

Moreover, your Admin Tools settings indicate that repeated security exceptions should result in the account being blocked. This happened and that's why you got blocked.

The correct solution is to increase your Session Lifetime to something more reasonable. On most of my sites I have it set to 30'. On my blog site it's even longer. This means my session will not expire when I am working in the backend of my site and I don't get blocked.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!