Support

Admin Tools

#30318 Issue where site goes offline for everyone showing the standard your are a bad person message

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Friday, 02 November 2018 18:17 CDT

edzz83
Hi Nick,

Just had a strange issue last night where an entire site went offline, it seems that somehow though all users to visit the site were being faced with the 'bad person' message from admin tools.

I disabled main.php by renaming, logged in, didnt see anything untoward, then turned back on main.php, and i was able to access again.

Now, this i put down to some kind of strange glitch, a one off, until it happened again today, on a totally different site, suddenly all visitors to the site are faced with this message.

I will need to investigate further to see if i can replicate the issue, however i wanted to post this to see if you had noticed anything similar and a possible fix.

I have a hunch that anytime an admin is blocked accessing query string wrong, then it might block all visitors instead of just a single IP block, i will test some more and report back too.

dlb
You have another server in front of your site, all traffic goes through it. When that server's IP is blocked, everybody becomes a bad guy.

Go to Web Application Firewall, Configure WAF, on the Basic Features tab, flip the value of "Enable IP workarounds". If it is No, make it Yes, or vice versa. That works 99% of the time.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

edzz83
Thanks Dale,

This has not happened before, must be something new with my host.

I see it says this reduces our security, can you elaborate, should I question my host about this?

dlb
There are two "from" IP addresses involved, the address of the visitor and the address of the second server. When everybody gets locked out, that indicates that the second server is locked out. That's a bad thing. The IP Workarounds setting flips the two IP addresses. So now instead of banning the second server, the visitor's IP address can be banned. It depends on how your host set up the addresses to be forwarded to your web server. The suggested setting is right most of the time, but not always.

It doesn't degrade security to have the setting set correctly. Security is degraded when all security exceptions are reported as being from the second server instead of the bad guy visitor.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!