Support

Admin Tools

#31515 UserID and password of failed logins not shown in emmail

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Wednesday, 07 August 2019 17:17 CDT

[email protected]
Website also has Community Builder 2.4.2 installed

Is it possible to include the username and password of the failed login attempt in the alert email that AdminTools generates?

The documentation at https://www.akeebabackup.com/documentation/admin-tools/web-application-firewall.html suggests that there os a configuration switch to make this happen, but I cannot see this in my install.

Thanks and best regards

S

nicholas
Akeeba Staff
Manager
We have completely removed the possibility of sending the username password for security reasons. If fact, two security reasons. First, what you receive by email is actually stored in the database, in the security exceptions log. Considering that in most real world cases the password stored was a user’s real, slightly mistyped password it created a massive security hole. Someone infiltrating your database would have the hashed passwords and a blueprint for many of them, making their job of cracking these passwords trivial. In our tests it took a mere few seconds to a few minutes (instead of hundreds of years) to crack these passwords using the slightly mistyped passwords as a starting point. The other obvious problem is that email is unencrypted and can be intercepted.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!