Post by lennyli » Wed Feb 08, 2017 4:58 pm

We are using opencart v1.5.6 and heard that this product can be hacked easiliy, having one of the weakness in having a default admin folder that is suspect-able to hackers guessing passwords etc.
We have tried renaming the admin folder to something else, and modified the files
admin\config.php
admin\view\stylesheet\adsmart_search.css
admin\view\template\report\adv_customers.tpl
vqmod\install\index.php

to replace the name of the text "/admin"

I can do such modification on another opencart installation without problems.

However, after doing this on one of our sites, the website stall and strange behaviour happens, being unresponsive, rendering only the homepage can be displayed while the other parts not returning a normal webpage.
I suspect that my predecessor coworker installed a Page Cache module that may be affecting this. While I tried to click the Disable Cache button, the dialog box said "can't disable, status: /var/www/vhosts/[mydomain]/PE/index.php is not writeable (permissions).

After I used the command chmod a+w to the index.php file, it still fails.
I wonder, do I have to do a chmod a+w to the PE folder? Anyone has experience modifying the admin folder location?

New member

Posts

Joined
Fri Jan 13, 2017 2:23 pm

Post by IP_CAM » Thu Feb 09, 2017 2:08 am

well, why make this so complicated ? There are easier ways, to protect your Admin access, like the one,
linked below, then, you don't have to worry, that some THINGS possibly don't function anymore, as they should.
Just to mention it!
Good Luck ! ;)
Ernie

SecureMyAdmin free, OC v.1.5.6.x, another similar Extension exists for OC v.2.x:
and someone also created an add-on-mod for this extension, so, also read the comment section!
Description:
Lots of people out there suggests you to rename the opencart's admin folder to prevent people from having
access to their administration backend or purchase plugins that changes your admin folder's name.
But by doing this, it breaks lots of pre-installed plugins and causing lots of problems such as upgrading or
install new plugins .
As renaming opencart's admin folder is not officially recommended by opencart.
The aim of SecureMyAdmin is to prevent Unauthorized people from accessing the administration backend
without renaming the admin folder allowing easy upgrades and worry free installation of other plugins.
SecureMyAdmin implements a secure key and value into the administrator backend URL ,only owners with
the key and value are able to access the administration backend.

https://www.opencart.com/index.php?rout ... n_id=15901
secure_admin.jpg

My Github OC Site: https://github.com/IP-CAM
5'600 + FREE OC Extensions, on the World's largest private Github OC Repository Archive Site.


User avatar
Legendary Member

Posts

Joined
Tue Mar 04, 2014 1:37 am
Location - Switzerland
Who is online

Users browsing this forum: Semrush [Bot] and 65 guests