Can’t gain access to your ACP suddenly? Please read!!

Get help with installation and running phpBB 3.3.x here. Please do not post bug reports, feature requests, or extension related questions here.
User avatar
Mick
Support Team Member
Support Team Member
Posts: 26715
Joined: Fri Aug 29, 2008 9:49 am

Can’t gain access to your ACP suddenly? Please read!!

Post by Mick »

If so, it’s more than likely an issue with mod_security as reported several times in the last week or so and it’s a server setting that your host needs to investigate. Contact the host and ask them to check if your admin control panel link has been blacklisted in their mod_security and or Imunify365 settings. If you don’t get a definitive answer from whoever you’re talking to tell them you’d like to speak to level 2 support or someone in charge. If you have any server error messages regarding this issue show them to your host.

Note: mod_security can be turned off altogether but in terms of server security all it really needs is whatever is triggering the error to be whitelisted by the host.
  • "The more connected we get the more alone we become" - Kyle Broflovski©
  • "The good news is hell is just the product of a morbid human imagination.
    The bad news is, whatever humans can imagine, they can usually create.
    " - Harmony Cobel©
🇬🇧
User avatar
thecoalman
Community Team Member
Community Team Member
Posts: 6040
Joined: Wed Dec 22, 2004 3:52 am
Location: Pennsylvania, U.S.A.

Re: Can’t gain access to your ACP suddenly? Please read!!

Post by thecoalman »

This should be fixed in 3.3.12 https://github.com/phpbb/phpbb/pull/6588

There is a pretty simple workaround that can be used temporarily as pointed out in this post.

When you get the prompt for username and password to login to the ACP before hitting the login button:
  • Right click on password box and select inspect or similar text depending on your browser. This will open the browsers developer console.
  • In the HTML section scroll down a little and find <input type="hidden" name="redirect" value="./../adm/index.php?sid=randomstring">
  • For the value= inline find ./../adm/ and replace it with ./
  • The result should look like this <input type="hidden" name="redirect" value="./index.php?sid=randomstring">
  • Hit the login button on the page and you should be able to login.
  • You can close the console once into the ACP.
You'll need to repeat this every time you are prompted for username and password to get into the ACP.
“Results! Why, man, I have gotten a lot of results! I have found several thousand things that won’t work.”

Attributed - Thomas Edison

Return to “[3.3.x] Support Forum”