Post by drubique » Fri Jun 25, 2010 1:35 am

If a visitor knows the OpenCart store system they can add '/admin' to the URL address and get to the backend login page. This is the same with Joomla which is considered a high potential security risk.

The Joomal solution is to add the 'jsecure' module which lets you add a secret password onto the URL; so that http://www.mysite.com/administrator becomes http://www.mysite.com/administrator/?secretword - now only the owner can dial up the admin login page.

http://extensions.joomla.org/extensions ... rity/12254

A simple module like this adds 'huge piece of mind' to store owners!

New member

Posts

Joined
Wed Mar 10, 2010 1:51 am

Post by Xsecrets » Fri Jun 25, 2010 4:52 am

if you are that worried about it there are simple instructions on the forum on how to rename the admin folder.

OpenCart commercial mods and development http://spotonsolutions.net
Layered Navigation
Shipment Tracking
Vehicle Year/Make/Model Filter


Guru Member

Posts

Joined
Sun Oct 25, 2009 3:51 am
Location - FL US

Post by drubique » Fri Jun 25, 2010 5:24 am

Xsecrets wrote:if you are that worried about it there are simple instructions on the forum on how to rename the admin folder.
Its a suggestion, as per the forum topic, for future development for OC as I am a keen supporter of the project.

If it was an issue then I would have posted this in the 'support' forum!!

New member

Posts

Joined
Wed Mar 10, 2010 1:51 am

Post by JAY6390 » Mon Jun 28, 2010 12:30 am

Something to be considered I guess, although renaming the folder gives just as much security, if not more, as with your version, it's still susceptible to CSRF attacks, but folder renaming does not have this issue

Image


User avatar
Guru Member

Posts

Joined
Wed May 26, 2010 11:47 pm
Location - United Kingdom

Post by SteveSherry » Mon Jun 28, 2010 4:56 am

I'm a fan of renaming the admin folder.....
or better still, just run it on a localhost, this way there can be no unauthorised access.

My Website ¦ Summer Madness Special Offer ¦


Active Member

Posts

Joined
Thu Apr 08, 2010 7:47 am
Location - Wirral, UK

Post by JAY6390 » Mon Jun 28, 2010 6:14 am

Very good suggestion, all that's needed is a db that allows remote access and roberts your mothers brother...

Image


User avatar
Guru Member

Posts

Joined
Wed May 26, 2010 11:47 pm
Location - United Kingdom

Post by i2Paq » Mon Jun 28, 2010 6:24 am

Yep, and the you Pc crashes or your internet-line fails and there is no other place to access your BO.......
Out the door goes the freedom of access and cloud-working.

Norman in 't Veldt
Moderator OpenCart Forums

_________________ READ and Search BEFORE POSTING _________________

Our FREE search: Find your answer FAST!.

[How to] BTW + Verzend + betaal setup.


User avatar
Global Moderator

Posts

Joined
Mon Nov 09, 2009 7:00 pm
Location - Winkel - The Netherlands

Post by SteveSherry » Mon Jun 28, 2010 6:35 am

i2Paq wrote:Yep, and the you Pc crashes or your internet-line fails and there is no other place to access your BO.......
Out the door goes the freedom of access and cloud-working.
I totally agree, but there are people in the world who are too scared to go out of their front door......

.....each to his own (or her own)

My Website ¦ Summer Madness Special Offer ¦


Active Member

Posts

Joined
Thu Apr 08, 2010 7:47 am
Location - Wirral, UK

Post by JAY6390 » Mon Jun 28, 2010 6:38 am

Of course, if you have access to the internet, you can always download another copy of OC and use the BO from that :)

Image


User avatar
Guru Member

Posts

Joined
Wed May 26, 2010 11:47 pm
Location - United Kingdom
Who is online

Users browsing this forum: No registered users and 10 guests