• 1

Read this first!

We do not monitor these forums. The forum is provided to exchange information and experience with other users ONLY. Forum responses are not guaranteed.

However, please submit a ticket if you have an active subscription and wish to receive support. Our ticketing system is the only way of getting in touch with RSJoomla! and receiving the official RSJoomla! Customer Support.

For more information, the Support Policy is located here.

Thank you!

TOPIC: Need Help with Admin Backend Attacker

Need Help with Admin Backend Attacker 12 years 8 months ago #18604

  • renico
  • renico's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 1
Someone keeps attempting to login to the administrator backend. This has happened on our website on a continuous basis for the past three days. We have installed RSFirewall and the message we receive is "There was an unsuccessful attempt to login into the backend section of your website using an unknown username.
Debug information:
username=admin password=admin2." (always a Different password)

These are the different IP addresses appearing in the System Logs
178.137.91.38, 178.137.160.204, 178.137.91.38, 176.8.22.77

How can i prevent this before they do get the Correct Username and Password.
They are also attacking our other websites. Thank you for your time
Kind regards: Renico
The administrator has disabled public write access.

Re: Need Help with Admin Backend Attacker 12 years 7 months ago #18714

  • wirecreative
  • wirecreative's Avatar
  • OFFLINE
  • Junior Boarder
  • Posts: 21
  • Thank you received: 2
RSFirewall will help you with this in a couple of different ways.

First of all, if you have a good administrative username/password combination (not "admin/1234"), they are unlikely to guess and get in successfully. They are checking for lazy admin logins. But even then it can be a nuisance to deal with all the alert emails.

In RSFirewall you can set an additional backend password that will screen these guys from even getting to your Joomla admin login screen, you can blacklist the ip addresses attempting to gain access, and newer versions also allow blocking access from certain counbtries (these attacks usually come from eastern Europe, Asia or Africa) and automatic ip blacklisting after so many failed attempts.
The administrator has disabled public write access.
  • 1

Read this first!

We do not monitor these forums. The forum is provided to exchange information and experience with other users ONLY. Forum responses are not guaranteed.

However, please submit a ticket if you have an active subscription and wish to receive support. Our ticketing system is the only way of getting in touch with RSJoomla! and receiving the official RSJoomla! Customer Support.

For more information, the Support Policy is located here.

Thank you!