osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 

Anyone can login my admin.php...Help plz!

This is a discussion on Anyone can login my admin.php...Help plz! within the osCommerce 2.2 Modification Help forums, part of the osCommerce 2.2 Forums category; I have already secured my osCommerce store with SSL and I have changed all the necessary values so that it ...


Go Back   osCommerce and osCMax shopping cart software forums > osCommerce 2.2 Forums > osCommerce 2.2 Modification Help

Register FAQ Members List Calendar Mark Forums Read


Free community membership! Fast easy FREE membership
Closed Thread

 

LinkBack Thread Tools
  #1  
Old 06-07-2004, 07:29 AM
Lurker
 
Join Date: Jun 2004
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
spectrumpower
Default Anyone can login my admin.php...Help plz!

I have already secured my osCommerce store with SSL and I have changed all the necessary values so that it will recognize it and it does no problem. The only problem is that anyone can access my admin account just by simply going to the admin.php. Is there any way for a password prompt or something to come up so that only I may access it?

Thanks!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #2  
Old 06-09-2004, 06:47 AM
Member
 
Join Date: May 2004
Posts: 31
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
seank123
Default

The easiest way to to add a user/password to the catalog/admin folders .htaccess file - check with your host to find out how to do it.

There are also a couple of mods that do it too:

http://www.oscommerce.com/community/...search,protect
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #3  
Old 06-09-2004, 09:52 AM
michael_s's Avatar
osCMax Developer

 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 10,331
Thanks: 68
Thanked 322 Times in 305 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default

See this to secure your install:

http://oscdox.com/modules.php?op=mod...20Installation
__________________
Michael Sasek
osCMax Developer


  • osCMax Templates - Hundreds of premium quality templates. New designs every month!

  • xShop for osCMax - Windows Based osCMax administration. Improved workflow, security, speed and convenience.

  • osCMax Hosting - From basic hosting to High Availability, Load Balanced arrays, the most experienced osCMax host.

  • osCMax Template Tutorial - Learn how to make your own custom templates and how to use the powerful features of the osCMax template system.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #4  
Old 06-10-2004, 11:25 AM
jpf's Avatar
jpf jpf is online now
Moderator

 
Join Date: Sep 2003
Location: Manitoba, Canada
Posts: 1,581
Thanks: 1
Thanked 84 Times in 71 Posts
Rep Power: 10
jpf is a glorious beacon of lightjpf is a glorious beacon of lightjpf is a glorious beacon of lightjpf is a glorious beacon of lightjpf is a glorious beacon of light
Default

The "other" option (in addition to above) is to delete or move the admin...

anyone that know OSC and finds out your site is using it can try the standard directories to hack into the ADMIN (if they get a login screen then they can try hacking in) - but if you move it so something random - unguessable then they will be hard to even find it...

www.yoursite.com/admin
www.yoursite.com/catalog/admin

- how about try:

http://www.yoursite.com/s0mEthinG_ra...ssd/myADM1Ndir
note: that is 's(zero)mE' and 'ADM(one)N'

(Note: Unix treat /ABC, /abc,/Abc,/AbC etc as all diffent files/directories....)

Good Luck!
__________________
JPF - osCMax Fourm Moderator
Try out our osCMax at: Live Catalog Demo
Limited access Admin: Live Admin Demo
Feel free to add products they way you want and then purchase them -=+=- Sorry nothing will be billed or shipped!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #5  
Old 09-02-2004, 09:34 PM
New Member
 
Join Date: Sep 2004
Posts: 10
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
Guile
Default

Thanks for this information, i was having the same problems and i appreciate the thoroughness of these three solutions. This is one of the best technical forums because of the people on it.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads

Thread Thread Starter Forum Replies Last Post
Admin Login torweb osCMax v2 Installation issues 4 04-18-2007 12:52 PM
Admin Login Problem - my customer can't login, I can pram0310 osCMax v1.7 Installation 2 10-29-2004 10:46 AM
Admin Login Help SyraxSinister osCMax v1.7 Installation 3 07-09-2004 06:37 AM
Well crap... admin login not allowing login-no errors tauras911 osCMax v1.7 Installation 2 07-06-2004 11:12 PM
admin Login? kholloi osCommerce 2.2 Installation Help 2 11-09-2003 01:15 AM


All times are GMT -8. The time now is 07:01 AM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO
http://www.oscmax.com/forums/
Copyright 2008 osCMax