Results 1 to 5 of 5

Anyone can login my admin.php...Help plz!

This is a discussion on Anyone can login my admin.php...Help plz! within the osCommerce 2.2 Modification Help forums, part of the osCommerce 2.2 Forums category; I have already secured my osCommerce store with SSL and I have changed all the necessary values so that it ...

      
  1. #1
    Lurker
    Join Date
    Jun 2004
    Posts
    3
    Rep Power
    0


    Default Anyone can login my admin.php...Help plz!

    I have already secured my osCommerce store with SSL and I have changed all the necessary values so that it will recognize it and it does no problem. The only problem is that anyone can access my admin account just by simply going to the admin.php. Is there any way for a password prompt or something to come up so that only I may access it?

    Thanks!

  2. #2
    Member
    Join Date
    May 2004
    Posts
    31
    Rep Power
    0


    Default

    The easiest way to to add a user/password to the catalog/admin folders .htaccess file - check with your host to find out how to do it.

    There are also a couple of mods that do it too:

    http://www.oscommerce.com/community/...search,protect

  3. #3
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,501
    Rep Power
    567
    Michael Sasek
    osCMax Developer


    osCmax installation service - Have our professionals install osCmax on your server - same day service!
    osCmax 2.0 User Manual - the must have beginners guide to osCmax v2.0

    Stay Up To Date with everything osCMax:
    Free osCMax Newsletters - Security notices, New Releases, osCMax News
    osCMax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

  4. #4
    jpf
    jpf is offline
    osCMax Testing Team
    jpf's Avatar
    Join Date
    Sep 2003
    Location
    Manitoba, Canada
    Posts
    2,688
    Rep Power
    22


    Default

    The "other" option (in addition to above) is to delete or move the admin...

    anyone that know OSC and finds out your site is using it can try the standard directories to hack into the ADMIN (if they get a login screen then they can try hacking in) - but if you move it so something random - unguessable then they will be hard to even find it...

    www.yoursite.com/admin
    www.yoursite.com/catalog/admin

    - how about try:

    http://www.yoursite.com/s0mEthinG_ra...ssd/myADM1Ndir
    note: that is 's(zero)mE' and 'ADM(one)N'

    (Note: Unix treat /ABC, /abc,/Abc,/AbC etc as all diffent files/directories....)

    Good Luck!
    JPF - osCMax Fourm Moderator - To contact, post on the forum or click here
    Try out our osCMax at: Live Catalog Demo
    Limited access Admin: Live Admin Demo
    Feel free to add products they way you want and then purchase them -=+=- Sorry nothing will be billed or shipped!

  5. #5
    New Member
    Join Date
    Sep 2004
    Posts
    10
    Rep Power
    0


    Default

    Thanks for this information, i was having the same problems and i appreciate the thoroughness of these three solutions. This is one of the best technical forums because of the people on it.

Similar Threads

  1. Admin Login
    By torweb in forum osCmax v2 Installation issues
    Replies: 16
    Last Post: 01-29-2010, 04:05 AM
  2. Admin Login Problem - my customer can't login, I can
    By pram0310 in forum osCMax v1.7 Installation
    Replies: 2
    Last Post: 10-29-2004, 11:46 AM
  3. Admin Login Help
    By SyraxSinister in forum osCMax v1.7 Installation
    Replies: 3
    Last Post: 07-09-2004, 07:37 AM
  4. Well crap... admin login not allowing login-no errors
    By tauras911 in forum osCMax v1.7 Installation
    Replies: 2
    Last Post: 07-07-2004, 12:12 AM
  5. admin Login?
    By kholloi in forum osCommerce 2.2 Installation Help
    Replies: 2
    Last Post: 11-09-2003, 01:15 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •