Post by dorkiedoode » Fri Nov 16, 2012 5:38 am

http://forum.opencart.com/viewtopic.php?f=19&t=26388

I uploaded the mod and implemented the security measures in the thread listed above but I am unsure if its working or not. I can still navigate my /cataloge, /system, /image, /cgi-bin in the root directory but if i go any further it will error 404. i thought it was not suppose to allow you to enter any of those folders in the place? As in www.store.com/catalog would error 404 then redirects you back to crickel? My site does not do that, it just errors out if you try to advance further into the directory of those folders but STILL allows you to access the them. For example www.store.com/catalog would work.

How can I make it that /cataloge, /system, /image, /cgi-bin folder not accessible to the public?

What is a more secure way to accessing www.store.com/admin ?

What about cpanel? www.store.com/cpanel

Thank you! I am new to creating website and this is my first one. I tried changing perms to all the folder to 744 but my website soon became nonfunctional...

Newbie

Posts

Joined
Fri Nov 16, 2012 4:34 am

Post by Tcalp » Fri Nov 16, 2012 11:23 am

To secure your admin folder I'd suggest this : http://www.opencart.com/index.php?route ... on_id=9281 which will display a 404 page to un-authorized internet addresses.

I don't think that there is much that you can do about cPanel / webmail / whm ? I could be wrong though.

for /image if you are just wanting to ensure that dir listings cannot be accessed, vqmod/xml contains an .htaccess file which removes directory listing capabilities, just drop it in ./image , and for /catalog and /system, I would suggest adding a re-write rule to re-direct to a 404 page.

Increase Page Speed (#1 rated commercial extension on OpenCart Marketplace)
15in1 Essential Extensions Value Pack Premium Customer Testimonials Reward Points Extended Admin Security Lockdown Suite

Image
irc.freenode.net #opencart


User avatar
Active Member

Posts

Joined
Wed Jul 06, 2011 1:49 pm

Post by Avvici » Fri Nov 16, 2012 11:33 am

Tcalp wrote:To secure your admin folder I'd suggest this : http://www.opencart.com/index.php?route ... on_id=9281 which will display a 404 page to un-authorized internet addresses.

I don't think that there is much that you can do about cPanel / webmail / whm ? I could be wrong though.

for /image if you are just wanting to ensure that dir listings cannot be accessed, vqmod/xml contains an .htaccess file which removes directory listing capabilities, just drop it in ./image , and for /catalog and /system, I would suggest adding a re-write rule to re-direct to a 404 page.
I'd second this extension. It's cheap for what it actually does. O0

User avatar
Expert Member

Posts

Joined
Tue Apr 05, 2011 12:09 pm
Location - Asheville, NC

Post by Tcalp » Fri Nov 16, 2012 12:09 pm

avvici wrote:I'd second this extension. It's cheap for what it actually does. O0
Thanks for the love muffin Avvici :)

Increase Page Speed (#1 rated commercial extension on OpenCart Marketplace)
15in1 Essential Extensions Value Pack Premium Customer Testimonials Reward Points Extended Admin Security Lockdown Suite

Image
irc.freenode.net #opencart


User avatar
Active Member

Posts

Joined
Wed Jul 06, 2011 1:49 pm

Post by dorkiedoode » Fri Nov 16, 2012 12:59 pm

Thank you for the reply guys :). My last two questions which will work out all the quirks in my website

How can I redirect store.com to www.store.com. I tried some methods but they do not work

How can I change the telephone field to something else?

Thanks a lot guys.

Newbie

Posts

Joined
Fri Nov 16, 2012 4:34 am

Post by dorkiedoode » Fri Nov 16, 2012 1:27 pm

Tcalp Can you write me a redirect script to 404? That is beyond my understanding of coding. i just barely learned about perms.

Newbie

Posts

Joined
Fri Nov 16, 2012 4:34 am
Who is online

Users browsing this forum: No registered users and 65 guests