Get the most out of your Centmin Mod LEMP stack
Become a Member

Security Error 1006 Access denied on my admin.php area

Discussion in 'System Administration' started by modder, Oct 29, 2021.

  1. modder

    modder Member

    70
    9
    8
    Dec 6, 2019
    Ratings:
    +14
    Local Time:
    11:45 AM
    I'm running latest xenforo on centminmod via cloudflare.

    Recently after my home IP changed I can no longer get access to the admin area of my xenforo.

    I believe I did have changed something to secure my admin area but I forgot what I did.


    I checked firewall rules in cloudflare but nothing special found. So it might be I've done something in centminmod? I'm not sure..
     
    Last edited: Oct 29, 2021
  2. eva2000

    eva2000 Administrator Staff Member

    47,498
    10,769
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +16,742
    Local Time:
    1:45 PM
    Nginx 1.19.x
    MariaDB 5.5/10.x
    in your nginx vhost for admin.php location context, did you set a IP address restriction to your ISP IP? Might need to update that
     
  3. modder

    modder Member

    70
    9
    8
    Dec 6, 2019
    Ratings:
    +14
    Local Time:
    11:45 AM
    nothing about "admin" found in the file /usr/local/nginx/conf/conf.d/mydomain.ssl.conf

    Currently, only one location (that particular IP) can get access to the admin area. I can do that with my mobile phone too with that wifi.

    I tried to run the following command in '/user/local/nginx' but resulted nothing.

    grep -rnw . -e '188\.109\.202\.129'
    grep -rnw . -e '188.109.202.129'
    grep -rnw . -e '188'

    Nothing even for grep -rnw . -e 'admin.php' and grep -rnw . -e 'admin\.php'

    where 188.109.202.129 (I modified the real IP here) is the IP address that works on the admin area.
     
    Last edited: Nov 1, 2021
  4. modder

    modder Member

    70
    9
    8
    Dec 6, 2019
    Ratings:
    +14
    Local Time:
    11:45 AM
    Found the cause of the problem. I configured the Zone Lockdown in Cloudflare...
     
  5. eva2000

    eva2000 Administrator Staff Member

    47,498
    10,769
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +16,742
    Local Time:
    1:45 PM
    Nginx 1.19.x
    MariaDB 5.5/10.x
    Ah that would explain things. You can switch to Cloudflare Access to protect logs instead. That's what I do for Xenforo and Wordpress logins :D
     
  6. modder

    modder Member

    70
    9
    8
    Dec 6, 2019
    Ratings:
    +14
    Local Time:
    11:45 AM
    Any tutorial for that? :)
     
  7. eva2000

    eva2000 Administrator Staff Member

    47,498
    10,769
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +16,742
    Local Time:
    1:45 PM
    Nginx 1.19.x
    MariaDB 5.5/10.x