Protection Mode

Overview & Setup

On-demand scanning finds problems after they happen. Protection Mode, powered by the optional MuRu Guard Shield plugin, checks requests as they reach Joomla and records matches in a sectioned Protection Log.

Enabling it

Make sure the Shield plugin is installed and enabled under System > Manage > Plugins, then turn on Protection Mode from the scanner's Settings panel. All protection switches are off by default -- nothing is auto-protected on install.

Switches

  • Protection Mode -- master switch that detects and logs every match.
  • Attack Blocking -- optional 403 block for high-confidence webshell, SPPB RCE, and known drop-filename matches.
  • Brute-Force Blocking -- optional IP blocking after repeated failed administrator login attempts.
  • Manual IP Access List -- always-allow or always-block specific IPs or CIDR ranges, checked before any pattern or threshold rule.
  • Country Blocking -- reject requests from chosen countries via a cached, fail-open GeoIP lookup.
  • Bad User-Agent Blocking -- reject known scanner/bot user agents.

Authenticated non-guest admin sessions are exempt from request-pattern and country blocking, so you can never lock yourself out by travelling or using a VPN.