Support

Admin Tools

#31112 Lots of attempts at wp-login - and related blacklisting

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Wednesday, 17 April 2019 17:17 CDT

palazzi
I have a very strange situation. Seems thta around March 4th, my site all of a sudden started taking on a ton of hackers trying to login to my Joomla site as if it were wordpress (i.e. going to /wp-login). Admin tools blocks it as it should and I have disabled 404 notifications (way too much noise as I'm getting around 100 attempts per day, up from 15-20). However, as these are likely bot-based, they try multiple times and as a result I see about 40-50 blacklist notifications per day. What's worrying me most is that this is causing me performance issues from both the processing of these and blocking them as well as a longer and more complex block list that is processed for every visit.

My value for auto blocking is 2 in 24 hours, block for 17 hours, permanently block after 2 - very broad. Do you have a suggestion to be more efficient on the system? Anything I can do to limit the auto block notifications that resulted from 404 attempts? I didn't see that - hopefully you can add it. I still log and review logs, but getting 50 messages of auto block is noisy and I fear a real notice will get lost.

Attaching a screen shot of the graph showing the WAF exceptions. Of those show, 99% are 404.

tampe125
Akeeba Staff
Hello,

first of all, please take a look at our page about seeing a lot of security exceptions all of sudden (spoiler alert: you don't have to worry).

Regarding resource usage, you shouldn't worry about it, since requesting 404 pages won't consume a lot of resources.
The 404 Shield feature will only block suspicious requests (ie trying to access WordPress administration while you're using Joomla), so it's quite hard to have false positives.
You can't setup custom blocking rules for each security exception type, but you can turn off email notifications for specific types. You can find such option inside the Configure WAF page, tab Logging.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!