Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> Is _admin_access.php A Security Risk?
bilbo--baggins
post Sep 7 2009, 04:38 PM
Post #1


Enthusiast
***

Group: Members
Posts: 54
Joined: 24-May 09
Member No.: 4,865



Reputation:   1  


I just found a file in my root directory called _admin_access.php which seems to allow access to the admin area without a password. Is this file a security risk, or is it there to specifically allow Avactis Support to get into the admin area?

I've temporarily removed this file until someone can assure me it's meant to be there!

The strange thing is that it's not in my test server.
Go to the top of the page
  
+Quote Post
mikemar921
post Sep 7 2009, 07:10 PM
Post #2


Hey, Look - I can change this now!!! :D
******

Group: Members
Posts: 512
Joined: 8-January 08
From: USA
Member No.: 4,180
Avactis 1.9.1 Build 8356


Reputation:   17  


Hi bilbo--baggins,

Where was that file located in your store? I just took a quick glance through the server for my installation of 1.8.2., and I did not see it listed.

Also, what was the original version that you installed (did you install 1.6 and upgrade over the years)? I am just wondering if this file is left over from previous versions, and that it might have been required in those previous versions, and not required for the most recent version 1.8.2.

Thanks
Mike


--------------------
Go to the top of the page
  
+Quote Post
bilbo--baggins
post Sep 8 2009, 05:33 PM
Post #3


Enthusiast
***

Group: Members
Posts: 54
Joined: 24-May 09
Member No.: 4,865



Reputation:   1  


1.8.2 was the first version that I installed. I'm not sure if the file is normally invisible, but I set my ftp client to show invisible files so that I could access .htaccess. It was in the root of the web folder.

I had a reply from Support saying it's used by them during debugging (they're currently trying to resolve issues with Maestro card payments via PayPal Website Payments Pro UK) and should not be a security risk because 1) it's limited to allowing entry by specific IP addresses and 2) they remove it when they're finished.
Go to the top of the page
  
+Quote Post
dvector
post Oct 20 2009, 06:06 AM
Post #4


Enthusiast
***

Group: Members
Posts: 81
Joined: 12-December 06
From: Scotland, UK
Member No.: 286
1.9.1


Reputation:   1  


That would be a useful file to have, I'm working on an admin addon but haven't figured out how to combine logons, any chance you could make that file available? :-)


--------------------
Go to the top of the page
  
+Quote Post
David Frost
post Oct 25 2009, 02:40 PM
Post #5


Avactis Support Engineer
****

Group: Administrators
Posts: 144
Joined: 22-April 09
From: Pentasoft Corp.
Member No.: 4,816
1.8.3


    


Hi Everyone,

As said by Bilbo, the file is safe, works only for a few our IP addresses (so the rest of the world can't use it), and deletes itself from server.

It's not a security risk.

@DVector Please write to us what you're trying to achieve, we'll advise on the best way to do it.


--------------------
David
Avactis Support Team
Go to the top of the page
  
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Lo-Fi Version Time is now: 8th September 2010 - 09:32 AM