Protection Mode
Overview & Setup
On-demand scanning finds problems after they happen. Protection Mode, powered by the optional MuRu Guard Shield plugin, checks requests as they reach Joomla and records matches in a sectioned Protection Log.
Enabling it
Make sure the Shield plugin is installed and enabled under System > Manage > Plugins, then turn on Protection Mode from the scanner's Settings panel. All protection switches are off by default -- nothing is auto-protected on install.
Switches
- Protection Mode -- master switch that detects and logs every match.
- Attack Blocking -- optional 403 block for high-confidence webshell, SPPB RCE, and known drop-filename matches.
- Brute-Force Blocking -- optional IP blocking after repeated failed administrator login attempts.
- Manual IP Access List -- always-allow or always-block specific IPs or CIDR ranges, checked before any pattern or threshold rule.
- Country Blocking -- reject requests from chosen countries via a cached, fail-open GeoIP lookup.
- Bad User-Agent Blocking -- reject known scanner/bot user agents.
Authenticated non-guest admin sessions are exempt from request-pattern and country blocking, so you can never lock yourself out by travelling or using a VPN.