1
lolo
french host banned admin.php
  • 2003/11/27 19:13

  • lolo

  • Just popping in

  • Posts: 5

  • Since: 2002/8/22


hi there!

I desperately need your help coz I'm not a PHP expert.
A french host banned access to all 'admin.php' files.
I tried to rename all of them for my site (as well as in all the other files they appeared in) but it just messed it all up.
Could someone please help me (and a few other users too ) by telling me if there's any way to rename "safely"?
thanx in advance!

l@u

2
skalpa
Re: french host banned admin.php
  • 2003/11/27 19:19

  • skalpa

  • Quite a regular

  • Posts: 300

  • Since: 2003/4/16


Someone from the hosting company told us this.

I'll be seeing this, but as I told her the fix may be a bit long...

Skalpa.>

3
lolo
Re: french host banned admin.php
  • 2003/11/27 19:51

  • lolo

  • Just popping in

  • Posts: 5

  • Since: 2002/8/22


I guess that if it's soooo dangerous, all the hosting companies around the world should do the same, shouldn't they?
has it happenned yet?

4
skalpa
Re: french host banned admin.php
  • 2003/11/27 20:27

  • skalpa

  • Quite a regular

  • Posts: 300

  • Since: 2003/4/16


Well I don't think it's soooooo dangerous
We try fixing security issues as we know about them (see 2.0.5.1, which has just been released to solve security issues).
However they reported being constantly attacked so I believe it's a good reason for them to take such a decision.
I also asked them for details about those "attacks" so I can check what they were supposed to do.

Also, try switching roles . I believe you'd prefer loosing access to your admin section during a few days than having all your data or files lost for ever.

Skalpa.>

5
lolo
Re: french host banned admin.php
  • 2003/11/27 20:53

  • lolo

  • Just popping in

  • Posts: 5

  • Since: 2002/8/22


yeah you're right
but my "client" is not very patient

6
Angie
Re: french host banned admin.php
  • 2003/11/28 0:16

  • Angie

  • Just popping in

  • Posts: 5

  • Since: 2003/11/27


:o) He Lolo,

c'est si dangereux parce-que n'importe quel neuneu sait ou commencer à attaquer: admin.php
Je mets 5 minutes à le trouver, 7h de recuperer ton mot de pass et ton adminnick avec une brutforce attaque, ensuite on te ridiculise devant ton client en te foutent ce genre d'index ( voir DIGITATTACKS sur www.zone-h.com ) :o)
Mais t'inquiete pas ... C'est pas une faille de securité , n'est pas ?

Sorry Skalpa but I tell to Lolo why the name of Admin.php is an danger. Because EVERYONE KNOW his name is ADMIN.PHP , so everyone know find him on a server. Only tapehttp://www.yourdomaine.com/admin.php <= OH I find :o) so I make a brut force attak against this page and I have 50 % chances to got the pass. ... After this everybody can put an index.html and OWNZ your to digits attacks on www.zone-h.com

You know, many of our clients use yours XOOPS and it's a fine systeme ( I like it ) but many of our client DO NOT KNOW SECURE heir Website or SQL data ...


Thanks anytime for readin and help

PS : I ask my boss for details of attacks and bring your the information soon ;o)

7
lolo
Re: french host banned admin.php
  • 2003/11/28 8:58

  • lolo

  • Just popping in

  • Posts: 5

  • Since: 2002/8/22


I didn't ask WHY it was banned but WHY the other hosting cies didn't do the same!!

8
recupsoft
Re: french host banned admin.php
  • 2003/11/28 10:24

  • recupsoft

  • Friend of XOOPS

  • Posts: 151

  • Since: 2003/10/30


I show an easy solution into the french forum
http://www.xoopsfr-forum.net/modules/newbb/viewtopic.php?viewmode=thread&topic_id=4628&forum=14&post_id=20578

9
lolo
Re: french host banned admin.php
  • 2003/11/28 10:35

  • lolo

  • Just popping in

  • Posts: 5

  • Since: 2002/8/22


merci , j'ai fait tout ça mais phpmyadmin me dit que j'ai une erreur de syntaxe quand je reintegre la bdd
j'en ai maaaarre!

10
Panos
Re: french host banned admin.php
  • 2003/11/28 11:19

  • Panos

  • Friend of XOOPS

  • Posts: 87

  • Since: 2003/3/20


WOW... Hold on for a sec here! What lolo reported is a very serious issue. Perhaps not that serious, like Skalpa wrote, but serious to the extent where it could drive a webmaster crazy!

Now, is there a way to 'spoof' admin.php and hide it from prying eyes? A post in English would be better

Login

Who's Online

205 user(s) are online (137 user(s) are browsing Support Forums)


Members: 0


Guests: 205


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Apr 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits