By Paul Murray on Monday, 15 June 2015
Posted in Technical Issues
Replies 45
Likes 0
Views 812
Votes 0
Hey SI team & users

I thought that I would post what I posted in the Siteground forum.
For the record I am EXTREMELY happy with Siteground.
BUT I need to get this to work.
Surly I am not alone with this problem.
Or maybe I have overlooked some tiny detail.
What ever...
This is my current "Going beyond the finalBUG" bug on my Site at the moment.
There has to be a better way!?!

here it goes:

Hi Site Ground

I run a site that is built mainly using components from the one and only Stackideas team.
They have been incredibly supportive answering and fixing dozens of things on my Site over the last 5 years.
Some times these fixes occur within hours. Sometimes things take a little longer 2/3 days.
What ever they are kind of fast :-)

This was in the day when I was at my old cranky hoster.
Where things were old, cranky and possibly insecure.
Now I am with you guys and frankly and loving it.

However!

Stackideas can not log into my Site.
They are changing there IP addresses all the time.
And sure I can ask them what there current IP address is.
And add it to the .htaccess file and we are good for another 24 hours.
Repeat and rinse!

I have several (Stackideas) issues on my Site that have not been solved for several weeks now.

The reason being this “permissions issue”

Please help me!
What is going on here?
There has to be a better way.
I love being at Siteground.
You guys are amazing really.

Please help me to find a solution so that I can work with Stackideas effectively.

thanks

Paul

end of Siteground post

thanks for anything that helps me get to the bottom of this

Paul
What do you want me to check here Paul? This thread is huge and I don't know where to start
·
Wednesday, 01 July 2015 23:01
·
0 Likes
·
0 Votes
·
0 Comments
·
Here is an update:

Thank you for the update and I apologize for the delayed reply.

As long as theyr connections are on an open port and their IP is not being blocked by the server firewall they should not have any issues to connect to your SiteGround account. More information on which ports are opened on our shared servers you may find on the following article from our knowledge base:

https://www.siteground.com/kb/which_ports_are_open_on_siteground_shared_servers/
·
Monday, 15 June 2015 16:44
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi SI team

I can imagine that you guys are on top of this
It is probably something else.

Maybe it is even my stupidity it has been know to happen.
For eg I did install a thing called: Securitycheck

http://extensions.joomla.org/extension/securitycheck

Can we please trouble shot this together.
I am around pretty much 8-18:00 CET
With a response time of an hourish
thanks

Paul
·
Monday, 15 June 2015 16:48
·
0 Likes
·
0 Votes
·
0 Comments
·
So I assume you have a whitelist for administrative access. With an offset in service hours and 24-hour IP rotation with SI, I really only see two obvious options:

Temporarily disable IP filtering for SI to help address the issue or

If the first two or three octets of SI's IP doesn't change, do a wildcard whitelist.

Either that or the more complicated route: clone your site on a subdomain with no security and have SI look at that. Clone the results to your main site.
·
Monday, 15 June 2015 17:04
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi David

Thanks for your input.
I even kind of understand what you are saying.

If the first two or three octets of SI's IP doesn't change, do a wildcard whitelist.


Sounds in my innocence best to me

I am curious what the SI team say...

thanks again

Paul
·
Monday, 15 June 2015 17:17
·
0 Likes
·
0 Votes
·
0 Comments
·
Rough example:

IP1: 192.168.1.1
IP2: 192.168.1.220
IP3: 192.168.40.3

The first two octets are the same for all 3 IPs, so your wildcard would look something like:

192.168.*.*

Of course, it all depends on your component if wildcards are even supported and how their syntax works.
·
Monday, 15 June 2015 17:45
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi SI Team

?

best

Paul
·
Tuesday, 16 June 2015 14:58
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Paul Murray,

I'm really sorry that delayed of this reply,

I would love to help you, but It would be best if you can temporary disable with your IP security firewall in your server/extension.

So that we can access in your Joomla backend.

Because our current IP address will always show different after leave from office.

Since you already submitted a lot of post in our forum and we still can't solve your issues due with IP security firewall.

Hope you understand.
·
Tuesday, 16 June 2015 19:35
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Arlex

Are you around for the next hour or two?
If this is something that Site ground need to do, I can give them the green light!
They usually respond within the hour.

I am looking into disabling this extension now:

http://extensions.joomla.org/extension/securitycheck

Just in case that is part of the problem!

I am obviously really anxious to get to the bottom of this

Please advise how to proceed

thanks

Paul
·
Tuesday, 16 June 2015 19:44
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Arlex

Securitycheck plugin disabled.
And I am logging out of my back end as I have the feeling that multiple logins with the same account cause problems.
If you need me to contact Siteground just let me know what I should tell them...

Also I have updated my site details.
i.e. FTP in the Site details section

best

Paul
·
Tuesday, 16 June 2015 19:51
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi SI team

It is 8am here in Berlin.
I am glued to my computer for the next 10 hours.
Please attempt to login in.
Securitycheck plugin disabled.
If you have problems logging in:

Plan 1A: Try to access my .httacces file via FTP and edit so that you can get in...
Plan 1B: If FTP does not work ask me for the password.
It is new and I have to the best of my knowledge entered it correctly in my Site details.

Plan 2: If 1A&1B do not work please reply to this post I will respond within an hour...

This is with a view to getting something cleared up that I posted about here:

http://stackideas.com/forums/who-can-search-view-profiles

*************************************************************************************************************************************

Last but by no means least please think about how we can avoid this long support reaction in the future.


*************************************************************************************************************************************

I am not blaming any one.
It is to a large extent my fault.
I am setting things up like fire walls which frankly I do not understand...

Thank you for your co-operation and help in advance

Paul
·
Wednesday, 17 June 2015 14:08
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Paul,

I'm really sorry that delayed of this reply,

Now is 3.34pm here.

Yes, it seems like I'm still hitting this permission issues :

403 - Forbidden Error
You are not allowed to access this address.
If the error persists, please contact the website webmaster.

This is my current IP address -> 175.136.62.32 ,can you try add my current IP address in your whitelist and see how it goes?

Because I already tried your method, search my IP address is it deny from your site .htaccess , but can't find out my IP address and I try using this :
Allow from 175.136.62.32

Also getting same permission error. Please advise.
·
Wednesday, 17 June 2015 15:52
·
0 Likes
·
0 Votes
·
0 Comments
·
hi Arlex

If I understand this correctly we are here:

Plan 1A: Done
Plan 1B: If Done
Plan 2: If 1A&1B do not work please reply to this post I will respond within an hour...

I have contacted Site ground and expect to be able to report back within the hour.

to be continued...
·
Wednesday, 17 June 2015 16:23
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi SI

Team this is what Siteground are now saying:

*******************************************************************************************
Thank you for the update.

I have checked and the IP address you provided is not blocked in our server firewall. I believe the issue is with your .htaccess file as there is a Deny rule in it.

If you have further questions do not hesitate to contact us.

Best Regards,

Stefan Stefanov
Technical Support Team

*******************************************************************************************

I will see if I can find this deny rule and remove it if only temporarily.
I imagine that I put it there/had some one put it there for a reason!
But frankly can not remember.

more later....
·
Wednesday, 17 June 2015 18:17
·
0 Likes
·
0 Votes
·
0 Comments
·
Here is where I am at
Below is my response to Siteground....

****************************************************************************************************

Hi Stefan

I do not understand!
Line 320 says: Allow from 175.136.61.168
This is the IP address from the SI team.
There is no mention of this address in the deny rules!?!
Which occur from lines 318 through to 341

Order Allow,Deny
Allow from all
Allow from 175.136.61.168
Allow from 175.136.62.32
# Cyveillance
deny from 38.100.19.8/29
deny from 38.100.21.0/24
deny from 38.100.41.64/26
deny from 38.105.71.0/25
deny from 38.105.83.0/27
deny from 38.112.21.140/30
deny from 38.118.42.32/29
deny from 65.213.208.128/27
deny from 65.222.176.96/27
deny from 65.222.185.72/29
Deny from env=bad_bot
#</Limit/>/administrator/

deny from 188.2.251.169
deny from 107.132.214.17
deny from 107.132.214.17
deny from 177.208.32.51
deny from 38.100.21.0/24
deny from 89.216.253.59

Please advise

Paul


****************************************************************************************************

more to come....
·
Wednesday, 17 June 2015 18:30
·
0 Likes
·
0 Votes
·
0 Comments
·
OK here is the latest I have...


****************************************************************************************************

Thank you for the update.

I have checked your issue and double checked for the IP address 175.136.61.168 in out server firewall. As that was not the case I have reviewed the permissions of your files and set them to 644 as this might be a reason for your issue.

I would suggest you to try again and should your issue persists please update this ticket with more information as to what is error you are seeing so we can investigate and assist you further.

Best Regards,

Stefan


****************************************************************************************************

Does this help us get to the bottom of this?

thanks

Paul
·
Wednesday, 17 June 2015 19:50
·
0 Likes
·
0 Votes
·
0 Comments
·
david@affinitypixel.com
Please email me with basic access; I'd like to see if US IPs are blocked.

Also, do a file search for multiple htaccess files. They can override each other.

http://wordpress.stackexchange.com/questions/63114/two-htaccess-files-located-in-different-directories

The first answer gives a good explanation on how it works.
·
Wednesday, 17 June 2015 23:17
·
0 Likes
·
0 Votes
·
0 Comments
·
Hello David,

Thank you for your help.
·
Thursday, 18 June 2015 17:40
·
0 Likes
·
0 Votes
·
0 Comments
·
David has been a huge help.
Doing some trouble shooting for me last night.
He has pointed me in the right direction saying that it is a problem at the Siteground end.
It is related to the Siteground Joomla Tools which I never touched.

Site ground are currently testing/looking into this.
They have broken/fixed/broken and are currently fixing again…
Definitely no longer stumbling around in the dark

I expect to be able to close this thread very soon.

thanks

Paul
·
Thursday, 18 June 2015 17:55
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Paul Murray,

That was great

Okay keep us updated then.

By the way, I'm really appreciated you help much Paul Murray here.
·
Thursday, 18 June 2015 18:17
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi SI team

Could you please try this again.
Frankly there have been so many attempts to get this working, I have lost track and do not know if it is currently working!
If you can not login please post your IP number and we try that way.

best

Paul
·
Tuesday, 23 June 2015 14:27
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Paul,

Sorry for late reply to this,

Yes, I've tried and still can't access

This is my current IP address -> 118.100.213.245
·
Wednesday, 24 June 2015 10:44
·
0 Likes
·
0 Votes
·
0 Comments
·
It may be a requirement to fully disable SiteGround's IP whitelisting until the problem can be resolved.
·
Wednesday, 24 June 2015 12:57
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Guys

OK I have gone into the Secure Admin Panel and put Arlex´s IP address in there.
I have edited the .htaccess file and put Arlex´s IP address in there.
See pretty much the last line:

 <IfModule mod_dtimeout.c>
<Files ~ ".php">
SetEnvIf Request_URI "index.php" DynamicTimeout=300
</Files>
</IfModule>


#To switch to PHP 4.4
#AddHandler application/x-httpd-php4 .php .php4 .php3
#To switch to PHP 5.0
#AddHandler application/x-httpd-php5 .php .php5 .php4 .php3<
#To switch to PHP 5.1
#AddHandler application/x-httpd-php51 .php .php5 .php4 .php3
#To switch to PHP 5.2
#AddHandler application/x-httpd-php52 .php .php5 .php4 .php3
#To switch to PHP 5.3
#AddHandler application/x-httpd-php53 .php .php5 .php4 .php3
#To switch to PHP 5.4
#AddHandler application/x-httpd-php54 .php .php5 .php4 .php3
#To switch to PHP 5.5
#AddHandler application/x-httpd-php55 .php .php5 .php4 .php3
#To switch to PHP 5.6
AddHandler application/x-httpd-php54 .php .php5 .php4 .php3
#To switch to the secure PHP 5.2 with Suhosin patch:
#AddHandler application/x-httpd-php52s .php .php5 .php4 .php3
########## Begin - ETag Optimization
## This rule will create an ETag for files based only on the modification
## timestamp and their size.
## Note: It may cause problems on your server and you may need to remove it
FileETag MTime Size
# AddOutputFilterByType is now deprecated by Apache. Use mod_filter in the future.
AddOutputFilterByType DEFLATE text/plain text/html text/xml text/css application/xml application/xhtml+xml application/rss+xml application/javascript application/x-javascript
# Enable expiration control
ExpiresActive On
# Default expiration: 1 hour after request
ExpiresDefault "now plus 1 hour"
# CSS and JS expiration: 1 week after request
ExpiresByType text/css "now plus 1 week"
ExpiresByType application/javascript "now plus 1 week"
ExpiresByType application/x-javascript "now plus 1 week"

<IfModule mod_headers.c>
Header set Access-Control-Allow-Origin: *
</IfModule>

# Image files expiration: 1 month after request
ExpiresByType image/bmp "now plus 1 month"
ExpiresByType image/gif "now plus 1 month"
ExpiresByType image/jpeg "now plus 1 month"
ExpiresByType image/jp2 "now plus 1 month"
ExpiresByType image/pipeg "now plus 1 month"
ExpiresByType image/png "now plus 1 month"
ExpiresByType image/svg+xml "now plus 1 month"
ExpiresByType image/tiff "now plus 1 month"
ExpiresByType image/vnd.microsoft.icon "now plus 1 month"
ExpiresByType image/x-icon "now plus 1 month"
ExpiresByType image/ico "now plus 1 month"
ExpiresByType image/icon "now plus 1 month"
ExpiresByType text/ico "now plus 1 month"
ExpiresByType application/ico "now plus 1 month"
ExpiresByType image/vnd.wap.wbmp "now plus 1 month"
ExpiresByType application/vnd.wap.wbxml "now plus 1 month"

ExpiresByType application/smil "now plus 1 month"
# Audio files expiration: 1 month after request
ExpiresByType audio/basic "now plus 1 month"
ExpiresByType audio/mid "now plus 1 month"
ExpiresByType audio/midi "now plus 1 month"
ExpiresByType audio/mpeg "now plus 1 month"
ExpiresByType audio/x-aiff "now plus 1 month"
ExpiresByType audio/x-mpegurl "now plus 1 month"
ExpiresByType audio/x-pn-realaudio "now plus 1 month"
ExpiresByType audio/x-wav "now plus 1 month"

# Movie files expiration: 1 month after request
ExpiresByType application/x-shockwave-flash "now plus 1 month"
ExpiresByType x-world/x-vrml "now plus 1 month"
ExpiresByType video/x-msvideo "now plus 1 month"
ExpiresByType video/mpeg "now plus 1 month"
ExpiresByType video/mp4 "now plus 1 month"
ExpiresByType video/quicktime "now plus 1 month"
ExpiresByType video/x-la-asf "now plus 1 month"
ExpiresByType video/x-ms-asf "now plus 1 month"

## EXPIRES CACHING ##

<IfModule mod_expires.c>/administrator/
ExpiresActive On
ExpiresByType image/jpg "access 1 year"
ExpiresByType image/jpeg "access 1 year"
ExpiresByType image/gif "access 1 year"
ExpiresByType image/png "access 1 year"
ExpiresByType text/css "access 1 month"
ExpiresByType text/html "access 1 month"
ExpiresByType application/pdf "access 1 month"
ExpiresByType text/x-javascript "access 1 month"
ExpiresByType application/x-shockwave-flash "access 1 month"
ExpiresByType image/x-icon "access 1 year"
ExpiresDefault "access 1 month"
</IfModule>
## EXPIRES CACHING ##
Options All -Indexes
RewriteEngine on
# Block Bad Bots & Scrapers
SetEnvIfNoCase User-Agent "Aboundex" bad_bot
SetEnvIfNoCase User-Agent "80legs" bad_bot
SetEnvIfNoCase User-Agent "360Spider" bad_bot
SetEnvIfNoCase User-Agent "^Java" bad_bot
SetEnvIfNoCase User-Agent "^Cogentbot" bad_bot
SetEnvIfNoCase User-Agent "^Alexibot" bad_bot
SetEnvIfNoCase User-Agent "^asterias" bad_bot
SetEnvIfNoCase User-Agent "^attach" bad_bot
SetEnvIfNoCase User-Agent "^BackDoorBot" bad_bot
SetEnvIfNoCase User-Agent "^BackWeb" bad_bot
SetEnvIfNoCase User-Agent "Bandit" bad_bot/adminifinalbug.net strator/
SetEnvIfNoCase User-Agent "^BatchFTP" bad_bot
SetEnvIfNoCase User-Agent "^Bigfoot" bad_bot
SetEnvIfNoCase User-Agent "^Black.Hole" bad_bot
SetEnvIfNoCase User-Agent "^BlackWidow" bad_bot
SetEnvIfNoCase User-Agent "^BlowFish" bad_bot
SetEnvIfNoCase User-Agent "^BotALot" bad_bot
SetEnvIfNoCase User-Agent "Buddy" bad_bot
SetEnvIfNoCase User-Agent "^BuiltBotTough" bad_bot
SetEnvIfNoCase User-Agent "^Bullseye" bad_bot
SetEnvIfNoCase User-Agent "^BunnySlippers" bad_bot
SetEnvIfNoCase User-Agent "^Cegbfeieh" bad_bot
SetEnvIfNoCase User-Agent "^CheeseBot" bad_bot
SetEnvIfNoCase User-Agent "^CherryPicker" bad_bot
SetEnvIfNoCase User-Agent "^ChinaClaw" bad_bot
SetEnvIfNoCase User-Agent "Collector" bad_bot
SetEnvIfNoCase User-Agent "Copier" bad_bot
SetEnvIfNoCase User-Agent "^CopyRightCheck" bad_bot
SetEnvIfNoCase User-Agent "^cosmos" bad_bot
SetEnvIfNoCase User-Agent "^Crescent" bad_bot
SetEnvIfNoCase User-Agent "^Custo" bad_bot
SetEnvIfNoCase User-Agent "^AIBOT" bad_bot
SetEnvIfNoCase User-Agent "^DISCo" bad_bot
SetEnvIfNoCase User-Agent "^DIIbot" bad_bot
SetEnvIfNoCase User-Agent "^DittoSpyder" bad_bot
SetEnvIfNoCase User-Agent "^Download\ Demon" bad_bot
SetEnvIfNoCase User-Agent "^Download\ Devil" bad_bot
SetEnvIfNoCase User-Agent "^Download\ Wonder" bad_bot
SetEnvIfNoCase User-Agent "^dragonfly" bad_bot
SetEnvIfNoCase User-Agent "^Drip" bad_bot
SetEnvIfNoCase User-Agent "^eCatch" bad_bot
SetEnvIfNoCase User-Agent "^EasyDL" bad_bot
SetEnvIfNoCase User-Agent "^ebingbong" bad_bot
SetEnvIfNoCase User-Agent "^EirGrabber" bad_bot
SetEnvIfNoCase User-Agent "^EmailCollector" bad_bot
SetEnvIfNoCase User-Agent "^EmailSiphon" bad_bot
SetEnvIfNoCase User-Agent "^EmailWolf" bad_bot/administrator/
SetEnvIfNoCase User-Agent "^EroCrawler" bad_bot
SetEnvIfNoCase User-Agent "^Exabot" bad_bot
SetEnvIfNoCase User-Agent "^Express\ WebPictures" bad_bot
SetEnvIfNoCase User-Agent "Extractor" bad_bot
SetEnvIfNoCase User-Agent "^EyeNetIE" bad_bot
SetEnvIfNoCase User-Agent "^Foobot" bad_bot
SetEnvIfNoCase User-Agent "^flunky" bad_bot
SetEnvIfNoCase User-Agent "^FrontPage" bad_bot
SetEnvIfNoCase User-Agent "^Go-Ahead-Got-It" bad_bot
SetEnvIfNoCase User-Agent "^gotit" bad_bot
SetEnvIfNoCase User-Agent "^GrabNet" bad_bot
SetEnvIfNoCase User-Agent "^Grafula" bad_bot
SetEnvIfNoCase User-Agent "^Harvest" bad_bot
SetEnvIfNoCase User-Agent "^hloader" bad_bot
SetEnvIfNoCase User-Agent "^HMView" bad_bot
SetEnvIfNoCase User-Agent "^HTTrack" bad_bot
SetEnvIfNoCase User-Agent "^humanlinks" bad_bot
SetEnvIfNoCase User-Agent "^IlseBot" bad_bot
SetEnvIfNoCase User-Agent "^Image\ Stripper" bad_bot
SetEnvIfNoCase User-Agent "^Image\ Sucker" bad_bot
SetEnvIfNoCase User-Agent "Indy\ Library" bad_bot
SetEnvIfNoCase User-Agent "^InfoNaviRobot" bad_bot
SetEnvIfNoCase User-Agent "^InfoTekies" bad_bot
SetEnvIfNoCase User-Agent "^Intelliseek" bad_bot
SetEnvIfNoCase User-Agent "^InterGET" bad_bot
SetEnvIfNoCase User-Agent "^Internet\ Ninja" bad_bot
SetEnvIfNoCase User-Agent "^Iria" bad_bot
SetEnvIfNoCase User-Agent "^Jakarta" bad_bot
SetEnvIfNoCase User-Agent "^JennyBot" bad_bot
SetEnvIfNoCase User-Agent "^JetCar" bad_bot
SetEnvIfNoCase User-Agent "^JOC" bad_bot
SetEnvIfNoCase User-Agent "^JustView" bad_bot
SetEnvIfNoCase User-Agent "^Jyxobot" bad_bot
SetEnvIfNoCase User-Agent "^Kenjin.Spider" bad_bot/administrator/
SetEnvIfNoCase User-Agent "^Keyword.Density" bad_bot
SetEnvIfNoCase User-Agent "^larbin" bad_bot
SetEnvIfNoCase User-Agent "^LexiBot" bad_bot
SetEnvIfNoCase User-Agent "^lftp" bad_bot
SetEnvIfNoCase User-Agent "^libWeb/clsHTTP" bad_bot
SetEnvIfNoCase User-Agent "^likse" bad_bot
SetEnvIfNoCase User-Agent "^LinkextractorPro" bad_bot
SetEnvIfNoCase User-Agent "^LinkScan/8.1a.Unix" bad_bot
SetEnvIfNoCase User-Agent "^LNSpiderguy" bad_bot
SetEnvIfNoCase User-Agent "^LinkWalker" bad_bot
SetEnvIfNoCase User-Agent "^lwp-trivial" bad_bot
SetEnvIfNoCase User-Agent "^LWP::Simple" bad_bot
SetEnvIfNoCase User-Agent "^Magnet" bad_bot
SetEnvIfNoCase User-Agent "^Mag-Net" bad_bot
SetEnvIfNoCase User-Agent "^MarkWatch" bad_bot
SetEnvIfNoCase User-Agent "^Mass\ Downloader" bad_bot
SetEnvIfNoCase User-Agent "^Mata.Hari" bad_bot
SetEnvIfNoCase User-Agent "^Memo" bad_bot
SetEnvIfNoCase User-Agent "^Microsoft.URL" bad_bot
SetEnvIfNoCase User-Agent "^Microsoft\ URL\ Control" bad_bot
SetEnvIfNoCase User-Agent "^MIDown\ tool" bad_bot
SetEnvIfNoCase User-Agent "^MIIxpc" bad_bot
SetEnvIfNoCase User-Agent "^Mirror" bad_bot
SetEnvIfNoCase User-Agent "^Missigua\ Locator" bad_bot
SetEnvIfNoCase User-Agent "^Mister\ PiX" bad_bot
SetEnvIfNoCase User-Agent "^moget" bad_bot
SetEnvIfNoCase User-Agent "^Mozilla/3.Mozilla/2.01" bad_bot
SetEnvIfNoCase User-Agent "^Mozilla.*NEWT" bad_bot
SetEnvIfNoCase User-Agent "^NAMEPROTECT" bad_bot
SetEnvIfNoCase User-Agent "^Navroad" bad_bot
SetEnvIfNoCase User-Agent "^NearSite" bad_bot
SetEnvIfNoCase User-Agent "^NetAnts" bad_bot
SetEnvIfNoCase User-Agent "^Netcraft" bad_bot
SetEnvIfNoCase User-Agent "^NetMechanic" bad_bot
SetEnvIfNoCase User-Agent "^NetSpider" bad_bot
SetEnvIfNoCase User-Agent "^Net\ Vampire" bad_bot
SetEnvIfNoCase User-Agent "^NetZIP" bad_bot
SetEnvIfNoCase User-Agent "^NextGenSearchBot" bad_bot
SetEnvIfNoCase User-Agent "^NG" bad_bot
SetEnvIfNoCase User-Agent "^NICErsPRO" bad_bot
SetEnvIfNoCase User-Agent "^niki-bot" bad_bot
SetEnvIfNoCase User-Agent "^NimbleCrawler" bad_bot
SetEnvIfNoCase User-Agent "^Ninja" bad_bot/administrator/
SetEnvIfNoCase User-Agent "^NPbot" bad_bot
SetEnvIfNoCase User-Agent "^Octopus" bad_bot
SetEnvIfNoCase User-Agent "^Offline\ Explorer" bad_bot
SetEnvIfNoCase User-Agent "^Offline\ Navigator" bad_bot
SetEnvIfNoCase User-Agent "^Openfind" bad_bot
SetEnvIfNoCase User-Agent "^OutfoxBot" bad_bot
SetEnvIfNoCase User-Agent "^PageGrabber" bad_bot
SetEnvIfNoCase User-Agent "^Papa\ Foto" bad_bot
SetEnvIfNoCase User-Agent "^pavuk" bad_bot
SetEnvIfNoCase User-Agent "^pcBrowser" bad_bot
SetEnvIfNoCase User-Agent "^PHP\ version\ tracker" bad_bot
SetEnvIfNoCase User-Agent "^Pockey" bad_bot
SetEnvIfNoCase User-Agent "^ProPowerBot/2.14" bad_bot
SetEnvIfNoCase User-Agent "^ProWebWalker" bad_bot
SetEnvIfNoCase User-Agent "^psbot" bad_bot
SetEnvIfNoCase User-Agent "^Pump" bad_bot
SetEnvIfNoCase User-Agent "^QueryN.Metasearch" bad_bot
SetEnvIfNoCase User-Agent "^RealDownload" bad_bot
SetEnvIfNoCase User-Agent "Reaper" bad_bot
SetEnvIfNoCase User-Agent "Recorder" bad_bot
SetEnvIfNoCase User-Agent "^ReGet" bad_bot
SetEnvIfNoCase User-Agent "^RepoMonkey" bad_bot
SetEnvIfNoCase User-Agent "^RMA" bad_bot
SetEnvIfNoCase User-Agent "Siphon" bad_bot
SetEnvIfNoCase User-Agent "^SiteSnagger" bad_bot
SetEnvIfNoCase User-Agent "^SlySearch" bad_bot
SetEnvIfNoCase User-Agent "^SmartDownload" bad_bot
SetEnvIfNoCase User-Agent "^Snake" bad_bot
SetEnvIfNoCase User-Agent "^Snapbot" bad_bot
SetEnvIfNoCase User-Agent "^Snoopy" bad_bot
SetEnvIfNoCase User-Agent "^sogou" bad_bot
SetEnvIfNoCase User-Agent "^SpaceBison" bad_bot
SetEnvIfNoCase User-Agent "^SpankBot" bad_bot/administrator/
SetEnvIfNoCase User-Agent "^spanner" bad_bot
SetEnvIfNoCase User-Agent "^Sqworm" bad_bot
SetEnvIfNoCase User-Agent "Stripper" bad_bot
SetEnvIfNoCase User-Agent "Sucker" bad_bot
SetEnvIfNoCase User-Agent "^SuperBot" bad_bot
SetEnvIfNoCase User-Agent "^SuperHTTP" bad_bot
SetEnvIfNoCase User-Agent "^Surfbot" bad_bot
SetEnvIfNoCase User-Agent "^suzuran" bad_bot
SetEnvIfNoCase User-Agent "^Szukacz/1.4" bad_bot
SetEnvIfNoCase User-Agent "^tAkeOut" bad_bot
SetEnvIfNoCase User-Agent "^Teleport" bad_bot
SetEnvIfNoCase User-Agent "^Telesoft" bad_bot
SetEnvIfNoCase User-Agent "^TurnitinBot/1.5" bad_bot
SetEnvIfNoCase User-Agent "^The.Intraformant" bad_bot
SetEnvIfNoCase User-Agent "^TheNomad" bad_bot
SetEnvIfNoCase User-Agent "^TightTwatBot" bad_bot
SetEnvIfNoCase User-Agent "^Titan" bad_bot
SetEnvIfNoCase User-Agent "^True_Robot" bad_bot
SetEnvIfNoCase User-Agent "^turingos" bad_bot
SetEnvIfNoCase User-Agent "^TurnitinBot" bad_bot
SetEnvIfNoCase User-Agent "^URLy.Warning" bad_bot
SetEnvIfNoCase User-Agent "^Vacuum" bad_bot
SetEnvIfNoCase User-Agent "^VCI" bad_bot
SetEnvIfNoCase User-Agent "^VoidEYE" bad_bot
SetEnvIfNoCase User-Agent "^Web\ Image\ Collector" bad_bot
SetEnvIfNoCase User-Agent "^Web\ Sucker" bad_bot
SetEnvIfNoCase User-Agent "^WebAuto" bad_bot
SetEnvIfNoCase User-Agent "^WebBandit" bad_bot
SetEnvIfNoCase User-Agent "^Webclipping.com" bad_bot
SetEnvIfNoCase User-Agent "^WebCopier" bad_bot
SetEnvIfNoCase User-Agent "^WebEMailExtrac.*" bad_bot
SetEnvIfNoCase User-Agent "^WebEnhancer" bad_bot
SetEnvIfNoCase User-Agent "^WebFetch" bad_bot
SetEnvIfNoCase User-Agent "^WebGo\ IS" bad_bot
SetEnvIfNoCase User-Agent "^Web.Image.Collector" bad_bot
SetEnvIfNoCase User-Agent "^WebLeacher" bad_bot
SetEnvIfNoCase User-Agent "^WebmasterWorldForumBot" bad_bot
SetEnvIfNoCase User-Agent "^WebReaper" bad_bot
SetEnvIfNoCase User-Agent "^WebSauger" bad_bot
SetEnvIfNoCase User-Agent "^Website\ eXtractor" bad_bot
SetEnvIfNoCase User-Agent "^Website\ Quester" bad_bot
SetEnvIfNoCase User-Agent "^Webster" bad_bot
SetEnvIfNoCase User-Agent "^WebStripper" bad_bot
SetEnvIfNoCase User-Agent "^WebWhacker" bad_bot
SetEnvIfNoCase User-Agent "^WebZIP" bad_bot
SetEnvIfNoCase User-Agent "Whacker" bad_bot
SetEnvIfNoCase User-Agent "^Widow" bad_bot
SetEnvIfNoCase User-Agent "^WISENutbot" bad_bot
SetEnvIfNoCase User-Agent "^WWWOFFLE" bad_bot
SetEnvIfNoCase User-Agent "^WWW-Collector-E" bad_bot
SetEnvIfNoCase User-Agent "^Xaldon" bad_bot
SetEnvIfNoCase User-Agent "^Xenu" bad_bot
SetEnvIfNoCase User-Agent "^Zeus" bad_bot
SetEnvIfNoCase User-Agent "ZmEu" bad_bot
SetEnvIfNoCase User-Agent "^Zyborg" bad_bot
# Vulnerability Scanners
SetEnvIfNoCase User-Agent "Acunetix" bad_bot
SetEnvIfNoCase User-Agent "FHscan" bad_bot
# Aggressive Chinese Search Engine
SetEnvIfNoCase User-Agent "Baiduspider" bad_bot
# Aggressive Russian Search Engine
SetEnvIfNoCase User-Agent "Yandex" bad_bot
#<Limit GET POST HEAD>
Order Allow,Deny
Allow from all
Allow from 175.136.61.168
Allow from 175.136.62.32
Allow from 118.100.213.245
# Cyveillance
deny from 38.100.19.8/29
deny from 38.100.21.0/24
deny from 38.100.41.64/26
deny from 38.105.71.0/25
deny from 38.105.83.0/27
deny from 38.112.21.140/30
deny from 38.118.42.32/29
deny from 65.213.208.128/27
deny from 65.222.176.96/27
deny from 65.222.185.72/29
Deny from env=bad_bot
#</Limit/>/administrator/

deny from 188.2.251.169
deny from 107.132.214.17
deny from 107.132.214.17
deny from 177.208.32.51
deny from 38.100.21.0/24
deny from 89.216.253.59


And I will contact Siteground right now asking them how to disable their "IP whitelisting" until the problem can be resolved.

(thanks again David)

And just as a reminder what the problem was...

http://stackideas.com/forums

I will publish the members page.

I am around pretty much most of the time for the next 8 hours...

fingers crossed

Paul
·
Wednesday, 24 June 2015 14:03
·
0 Likes
·
0 Votes
·
0 Comments
·
OK here is the latest from Siteground:

Hello Paul,

I checked and the IP you provided is not blocked in any of our Firewalls and should be able to access your website.
However if the extension is attempting an outgoing connection, those are forbidden by default on our shared servers. We can allow the outgoing connection but we will need a port as well.

Looking forward to your response.

Best Regards,

Georgi Milkov
Customer Service Department
·
Wednesday, 24 June 2015 14:25
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Paul Murray,

Sorry for late reply to this,

Finally I can access in your Joomla backend now.

Since we are keep trying access in your Joomla backend, I have lost what is your current issues now.

May i know what is you current issues?
·
Thursday, 25 June 2015 12:07
·
0 Likes
·
0 Votes
·
0 Comments
·
hi Arlex

Hurahhhhhhhhhhhhhhhhhhhhhhhh

As a matter of interest do you have the same IP as yesterday?
Or is it a new one?

A reminder what the problem was...

http://stackideas.com/forums/who-can-search-view-profiles

I will publish the members page.

I am around pretty much most of the time for the next 8 hours...

fingers crossed

Paul
·
Thursday, 25 June 2015 13:52
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi SI team

Just pushing this back up to the top of the pile
Can you get in today?

A reminder what the problem was...

http://stackideas.com/forums/who-can-search-view-profiles

Paul
·
Friday, 26 June 2015 13:38
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Paul,

Yes, I'm still investigate on this, and seems like your server blocked my IP address again.

This is my current IP address 175.143.133.250

By the way, I have temporary disabled this 3 thing from your backend, check my screenshot : http://screen.stackideas.com/2015-06-26_1538.png

Because when I view your homepage is showing blank page, after I enabled the error reporting to maximum, it point up this component causing this issues.
·
Friday, 26 June 2015 15:47
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Arlex

I have added your IP address to the .htacces file.
Please try again

I am just double checking here.
You are having difficulty logging in, in the front end as a "member" yeah?
Because assuming that this fails again and again it is a big problem for a members driven Site.

Let me know if you need anything.
I will be around...

thanks

Paul
·
Friday, 26 June 2015 16:06
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Paul Murray,

Thanks for helping this again.

But I do not know why I can't access your backend now.

By the way, We already do some debugging on your site just now and I believe one of your advanced filter search is based on your "Multilist" custom field, can you double check this few user profile custom field is it set this "Multilist" custom field privacy to Everyone?

Check my screenshot below.

If yes, you have to revert back all of their this "Multilist" custom field privacy to Everyone from your backend > Easysocial > profile type > select your profile type > Privacy tab > 'Who can view my multi list field' to Everyone. > and tick this option Tick the checkbox to reset all user's default privacy under this profile. ( This will also reset previous privacy settings of items belong to the users.) > save
·
Friday, 26 June 2015 16:56
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Arlex

Ok so maybe there is end in sight with respect to my Search issue.
I will have a look at it now.

But in the mean time...
You can not get in to the back end!!!

Can you please describe the issues that you have had logging in so far.
And I will pass this on to Siteground.
Security is well and good but this seems to be overkill!?!

more to follow...

Paul
·
Friday, 26 June 2015 17:07
·
0 Likes
·
0 Votes
·
0 Comments
·
Hello Paul Murray,

Okay, keep us updated then.

Do you mean when i trying to login on your backend? If yes, it actually same as before what i hitting that permission issues.
·
Friday, 26 June 2015 17:17
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Arlex

I simply do not understand this.

Why do I have to add your IP address so that you can access the front end.
If you I/you have problems logging in at the front end then maybe other people do as well!

a) Can you login at the front end with your current IP address?

b) Can you login at the back end with your current IP address?
HINT it is possible that doing both at the same time is also causing probelms
i.e. trying to login front/back at same time.

Here is a description of what I am seeing at my end:

I note that I am already logged in (front end)!
Please see my screen shot below.
I guess that you are still logged in as me.
I get an invalid token. OK

I try logging in as some one else e.g. BRUCE (same password as for paurray also in the front end)
Also see http://109.199.123.197:81/stream
Where I should see http://finalbug.net/stream
But do not get in...

I go to the back end
http://finalbug.net/administrator/index.php
And I get a blank page!!! THIS IS NEW.

I open another browser
http://finalbug.net/administrator/index.php
And see the login page and try to login as paurray
And I get a blank page!!!
This is possibly because you seem to be logged in as paurray at the front end

I do a refresh but still do not see the admin page.
I close the browser and try to login to admin as BRUCE
And get a blank page!!! Back end again...

Maybe this is a lead:
At one point I noticed an error at the top of the browser:
JCacheControllerPage compatible page.php
or similar!?!

Is it possible that this is the part of the problem.
If not it would be a huge help if you could give me a blow by blow description of the problems you are encountering so that I can talk to Siteground about this

best

Paul
·
Friday, 26 June 2015 17:46
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi SI Team

******************************

latest from Site Ground regarding the blank page:

Thank you for the update Paul.

I have investigated the issue carefully after recreating it (checked PHP versions, cache-related settings, .htaccess rewrite rules, configuration.php, etc.) however I could not find the reason for it.

That's why I would suggest that we try to restore the website from the last backup when it was working properly, if you wish - this will bring it to a working condition in terms of the admin page.

If you agree with that, you can try restoring the website on your own following the instructions below:

https://www.siteground.com/search.htm?q=backup+restore

From the last date within the last 30 days that we store backups for, that the website's admin page was working.

Normally the backup restore is performed as a paid service when performed by our team, however, please note that, because of its time consuming nature. For it, you can submit a ticket from your User Area - Support - Open a support ticket - Development services - Backup restore).

******************************
This is really frustrating

Paul
·
Friday, 26 June 2015 21:25
·
0 Likes
·
0 Votes
·
0 Comments
·
For the record I have a version of the site here:

http://upgrade.finalbug.net/administrator/index.php

That I was preparing for an upgrade to Joomla 3.x

The same login etc work for this Site as well
·
Friday, 26 June 2015 21:53
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Paul Murray,

I'm really sorry that delayed of this reply,

I simply do not understand this.
Why do I have to add your IP address so that you can access the front end.
If you I/you have problems logging in at the front end then maybe other people do as well!
a) Can you login at the front end with your current IP address?

Hmm, if I recall correctly, I only ask add my IP address in your .htaccess file for login in your backend.
And I didn't have frontend login issues in previously.

b) Can you login at the back end with your current IP address?
HINT it is possible that doing both at the same time is also causing probelms
i.e. trying to login front/back at same time.

Yes, I've tried now access in your frontend and backend with your previous domain name, all not working now.

Here is a description of what I am seeing at my end:
I note that I am already logged in (front end)!
Please see my screen shot below.
I guess that you are still logged in as me.
I get an invalid token. OK

I try logging in as some one else e.g. BRUCE (same password as for paurray also in the front end)
Also see http://109.199.123.197:81/stream
Where I should see http://finalbug.net/stream
But do not get in...

I go to the back end
http://finalbug.net/administrator/index.php
And I get a blank page!!! THIS IS NEW.

I open another browser
http://finalbug.net/administrator/index.php
And see the login page and try to login as paurray
And I get a blank page!!!
This is possibly because you seem to be logged in as paurray at the front end

I do a refresh but still do not see the admin page.
I close the browser and try to login to admin as BRUCE
And get a blank page!!! Back end again...

Maybe this is a lead:
At one point I noticed an error at the top of the browser:
JCacheControllerPage compatible page.php
or similar!?!

Is it possible that this is the part of the problem.
If not it would be a huge help if you could give me a blow by blow description of the problems you are encountering so that I can talk to Siteground about this

I'm sorry to heard that... After you restore the site, is it everything okay now?
·
Saturday, 27 June 2015 01:46
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Arlex

I am going on holidays for 4 days
More to come the middle of next week.

thanks for your patience

Paul
·
Saturday, 27 June 2015 02:18
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Paul Murray,

Nice Enjoy your holiday
·
Saturday, 27 June 2015 13:00
·
0 Likes
·
0 Votes
·
0 Comments
·
HIi Arlex & Si Team back for more

Latest from Siteground:

I am sorry for the delay. We found where the issue comes from. It is because your JCE extension.

===========================
[01-Jul-2015 06:02:43 CST6CDT] PHP Fatal error: Call to private method WFModelEditor::getPlugins() from context 'WFEditor' in /home/finalbug/public_html/components/com_jce/editor/libraries/classes/editor.php on line 170
===========================

I disabled "JCE Editor", " plg_editors_jce", "Quick Icon - JCE File Browser" and "System - JCE MediaBox" and now the admin panel for your website is working normally.

Let us know if you need anything else.

Best Regards,
Zdravko Zamfirov
Technical Support Team

I need your IP address? It is currently 13:32 where I am at and I am around for another 6 hours at least...
Otherwise to be continued tomorrow....

thanks

Paul
·
Wednesday, 01 July 2015 19:33
·
0 Likes
·
0 Votes
·
0 Comments
·
Hello Paul,

We have so many different ip addresses because sometimes some of us work from home after hours and really, I don't see why is Siteground is preventing our ip address

This is my current IP address, 210.186.223.112
·
Wednesday, 01 July 2015 22:16
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Mark

I added your IP address in the Siteground Joomla Toolkit.
I am out for the next hour but if there is anything in 1 hour + that I can do, I am happy to oblige.

thanks

Paul
·
Wednesday, 01 July 2015 22:56
·
0 Likes
·
0 Votes
·
0 Comments
·
I believe the original issue was here:

http://stackideas.com/forums/who-can-search-view-profiles

This thread pertains to access issues.
·
Wednesday, 01 July 2015 23:27
·
0 Likes
·
0 Votes
·
0 Comments
·
Yes David is of course correct.

I am going to put this thread to bed as it is long and painful.

thanks to all involved

Paul
·
Wednesday, 01 July 2015 23:49
·
0 Likes
·
0 Votes
·
0 Comments
·
Thanks for updating Paul
·
Wednesday, 01 July 2015 23:58
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post