The Joomla! Forum ™



Forum rules


Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Wed Aug 01, 2012 4:12 am 
Joomla! Fledgling
Joomla! Fledgling

Joined: Wed Aug 01, 2012 3:19 am
Posts: 2
I understand this is slightly off from a pure security topic, but I would like to explain my issue in detail first before you discard me completely :)

Here is my issue in the chronological order of the events:

1. 3 days back, I noticed I can not access the joomla admin page from any machine from my home broadband. If I try to access, the server simply drops the connection. But I can browse all the other pages of my website.

2. I can successfully login to joomla admin from the same machines if I use some other ISP. So the problem only happens when browsing from specific set of IP addresses of my home broadband provider.

3. Next I observed, the problem is not restricted for /administrator account only. It's basically with any *.php page. If I want to open any URL of my site that contains *.php (using my home broadband), server drops the connection. So basically:
Code:
example.com/administrator ===> Works!
example.com/administrator/index.php ===> does not work (server drops the connection)

Since I am using SEF URL with .html extension for the front end pages, I can access them from any machine under my home broadband. But as backend use index.php page - I can not use the backend. Similarly, I can not access any other .php page (e.g. the fpa-en.php page placed in my root)

4. I have done simple things like - rebooting my home router / clearing caches in browsers, server / contacting my server admin and ensuring that there is no firewall level IP based filtering for my outward IP of my BB service / disabling CDN / checking in .htaccess for any banned IP etc. with no result.

5. Finally, yesterday night, my server admin informed me that since the time I am facing the issue - they logged a huge series of SQL Injection attacks on joomla /component/search module - but the attack was blocked by "mod_security" module in the Apache. And the attackers IP addresses were mostly from the same range of the IP addresses that my home broadband service provider use. We tried disabling "mod_security" but situation did not change.

Sorry for the long post, but if you have not read the full and directly came to this para :) here is short brief: Something causing the web server to drop the connection when trying to access any *.php page directly from a specific IP range.


Top
 Profile  
 
PostPosted: Thu Aug 02, 2012 4:10 am 
Joomla! Fledgling
Joomla! Fledgling

Joined: Wed Aug 01, 2012 3:19 am
Posts: 2
This problem has been resolved now. The problem was caused because when Apache mod_security blocked the SQL injection attacks, it also triggered csf Firewall to ban the IP


Top
 Profile  
 
PostPosted: Fri Aug 03, 2012 3:50 am 
User avatar
Joomla! Master
Joomla! Master

Joined: Mon Aug 29, 2005 10:17 am
Posts: 11984
Location: Netherlands/ UK/ S'pore/Jakarta/ North America
Than can you please ad the "resolved" icon Image to your very first post?

Leo 8)

_________________
--- Joomla Professional Support Services :: http://gws-desk.com ---
--- Joomla Professional and Specialized Hosting :: http://gws-host.com ---
--- Ready to Roll Joomla! Web Sites : 1 - 7 days only! :: @ gws-market.com ---


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 



Who is online

Users browsing this forum: No registered users and 7 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group