Secure 2.3.1
#1
Posted 09 April 2011 - 04:23 PM
This evidently does not work. I cannot login.
After lengthy effort from the host, they finally removed password protection from the admin directory
so that I can login.
What options are available to secure 2.3.1 version?
Are procedures different from the older versions?
Thank you in advance
#2
Posted 09 April 2011 - 05:30 PM
Go to "Administrators" in your shops admin .. and follow the instructions given there
Check out my profile [click here] for information on professional services, custom coding, templates, SEO optimization, modifications, commercial support and help.
#3
Posted 09 April 2011 - 06:00 PM
toyicebear, on 09 April 2011 - 05:30 PM, said:
Go to "Administrators" in your shops admin .. and follow the instructions given there
Thank you for you response. I now have look at the Administrators Area and see:
The following files need to be writable by the web server to enable the htaccess/htpasswd security layer:
" /home/zappersu/public_html/catalog/admin/.htaccess
/home/zappersu/public_html/catalog/admin/.htpasswd_oscommerce
Reload this page to confirm if the correct file permissions have been set."
I must be missing something simple, but I do not see the files in the admin directories.
Do I have to create them some how?
#4
Posted 09 April 2011 - 06:12 PM
Check out my profile [click here] for information on professional services, custom coding, templates, SEO optimization, modifications, commercial support and help.
#5
Posted 09 April 2011 - 06:30 PM
toyicebear, on 09 April 2011 - 06:12 PM, said:
Yes, I am looking through the cpanel and do not see those 2 files in the admin folder.......
#6
Posted 09 April 2011 - 07:33 PM
Working with osCommerce 2.3.1
Add-Ons so far Installed:
Add date and order number to invoice and packing slip,
Products Cycle Slideshow,
Detailed Monthly Sales,
Holiday Settings,
Tracking Module for 2.3
#7
Posted 09 April 2011 - 08:35 PM
Xpajun, on 09 April 2011 - 07:33 PM, said:
That is very interesting.....I would have thought that you should use a different pass and user.
But what about changing the permissions on the files that I can not see?
1. public_html/catalog/admin/.htaccess
2. public_html/catalog/admin/.htpasswd_oscommerce
#8
Posted 10 April 2011 - 07:51 AM
oscbeginner99, on 09 April 2011 - 08:35 PM, said:
If you manage to get the osC .htaccess protection working that is exactly what it will do - produce .htaccess protection with the same username and password
oscbeginner99, on 09 April 2011 - 08:35 PM, said:
1. public_html/catalog/admin/.htaccess
2. public_html/catalog/admin/.htpasswd_oscommerce
In your cPanel file manager do you have a check box to show hidden files?
Working with osCommerce 2.3.1
Add-Ons so far Installed:
Add date and order number to invoice and packing slip,
Products Cycle Slideshow,
Detailed Monthly Sales,
Holiday Settings,
Tracking Module for 2.3
#9
Posted 10 April 2011 - 08:09 PM
Xpajun, on 10 April 2011 - 07:51 AM, said:
If you manage to get the osC .htaccess protection working that is exactly what it will do - produce .htaccess protection with the same username and password
In your cPanel file manager do you have a check box to show hidden files?
Thank you Xpajun,
I was not aware that these would be hidden files. Thank you very much...now I changed these to 777 and I hope
that this is correct.
#10
Posted 04 October 2011 - 08:52 PM
oscbeginner99, on 10 April 2011 - 08:09 PM, said:
I was not aware that these would be hidden files. Thank you very much...now I changed these to 777 and I hope
that this is correct.
Forum, Thanks Designing New Themes the Easy Way, how-to-set-backgrounds.
my contributions Add Multiple Product In Product Listing 2.3.1 v.1.0 and Multiple Attribute entry boxes in product info page v1.0 for 2.3.1
#11
Posted 04 October 2011 - 09:50 PM
I keep getting:
Error Additional Protection With htaccess/htpasswd This osCommerce Online Merchant Administration Tool installation is not additionally secured through htaccess/htpasswd means. The following files need to be writable by the web server to enable the htaccess/htpasswd security layer: /home/ZZZZZZ/public_html/catalog/ZZZZZZ/.htaccess /home/ZZZZZZ/public_html/catalog/ZZZZZZ/.htpasswd_oscommerce Reload this page to confirm if the correct file permissions have been set.
I've removed the .htpasswd_oscommerce file
Within my control panel I've added a username and password (same as admin) for my admin folder.
I've also tried a ton of different permission combinations and no luck...
#12
Posted 05 October 2011 - 08:10 PM
ShallonCimelus, on 04 October 2011 - 09:50 PM, said:
I keep getting:
Error Additional Protection With htaccess/htpasswd This osCommerce Online Merchant Administration Tool installation is not additionally secured through htaccess/htpasswd means. The following files need to be writable by the web server to enable the htaccess/htpasswd security layer: /home/ZZZZZZ/public_html/catalog/ZZZZZZ/.htaccess /home/ZZZZZZ/public_html/catalog/ZZZZZZ/.htpasswd_oscommerce Reload this page to confirm if the correct file permissions have been set.
I've removed the .htpasswd_oscommerce file
Within my control panel I've added a username and password (same as admin) for my admin folder.
I've also tried a ton of different permission combinations and no luck...
Forum, Thanks Designing New Themes the Easy Way, how-to-set-backgrounds.
my contributions Add Multiple Product In Product Listing 2.3.1 v.1.0 and Multiple Attribute entry boxes in product info page v1.0 for 2.3.1
#13
Posted 05 October 2011 - 08:56 PM
peteravu, on 05 October 2011 - 08:10 PM, said:
I've also cleared my browser of all files, different browser and different computer and still the same issue.
Anyone have another idea?
TIA
#14
Posted 06 October 2011 - 10:29 PM
Anyone have any other ideas?
#15
Posted 06 October 2011 - 11:08 PM
Regards
Jim
Banners Box 2.3.x Support
Categories Accordion Box 2.3.x Support
Categories Images Box 2.2x 2.3.x Support
Closest Shipper 2.2x Support
Document Manager 2.2x Support
Generic Box 2.3.x Support
Get 1 Free 2.2x Support
jQuery Banner Rotator 2.2x 2.3.x Support
Modular Front Page 2.3.x Support
Modular SEO Header Tags 2.3.x Support
MVS 2.2x Support
PDF Datasheet 2.3.x Support
Price Updater 2.2x
Products Specifications 2.2x 2.3.x Development Version Support Bugs/Suggestions
Request a Review 2.2x - 2.3.x Support
Similar Products Box 2.2x
Specials Image Overlay 2.3x Support
Theme Switcher 2.3.x Support
#16
Posted 07 October 2011 - 12:12 AM
Forum, Thanks Designing New Themes the Easy Way, how-to-set-backgrounds.
my contributions Add Multiple Product In Product Listing 2.3.1 v.1.0 and Multiple Attribute entry boxes in product info page v1.0 for 2.3.1
#17
Posted 07 October 2011 - 06:06 AM
666 is generally the writable setting for files.
- Another discussion about infected files ::here::
- A discussion on file permissions ::here::
- Site hacked? Should you upgrade or not, some thoughts ::here::
- Ignore this link - just a honeypot site to test my ideas out for osC_Sec and allow the site to be picked up by attackers.
- Fix the admin login bypass exploit here
#18
Posted 07 October 2011 - 01:33 PM
So after messing with the permissions more, I got a 500 Error and was no longer able to access the admin side of osCom. I deleted everything and started completely fresh.
Installation completed, no issues. Go into the admin and get the following error:
Error Additional Protection With htaccess/htpasswd This osCommerce Online Merchant Administration Tool installation is not additionally secured through htaccess/htpasswd means. Enabling the htaccess/htpasswd security layer will automatically store administrator username and passwords in a htpasswd file when updating administrator password records. Please note, if this additional security layer is enabled and you can no longer access the Administration Tool, please make the following changes and consult your hosting provider to enable htaccess/htpasswd protection: 1. Edit this file: /home/zzzz/public_html/catalog/zzzz/.htaccess Remove the following lines if they exist: ##### OSCOMMERCE ADMIN PROTECTION - BEGIN ##### AuthType Basic AuthName "osCommerce Online Merchant Administration Tool" AuthUserFile /home/zzzz/public_html/catalog/zzzz/.htpasswd_oscommerce Require valid-user ##### OSCOMMERCE ADMIN PROTECTION - END ##### 2. Delete this file: /home/zzzz/public_html/catalog/zzzz/.htpasswd_oscommerceThis time; I clicked on my admin user > edit > put in same password and checked the protect with .htaccess > save.
Refresh pop-up comes up, input login info and error is gone!
The first time I just checked "protect with .htaccess..." and did NOT put a password in, because it says "New Password". I believe that was the root of all my issues.
I read the directions several times and they are a little lax with this one step. I would recommend adding a little more to say "insert same password in the 'New Password' field and check the protection" for those like me that thought the original password would stay if left blank.
,htaccess and .htpasswd_oscommerce are in my admin dir with permissions 644.
Thank you all for your help.
Edited by ShallonCimelus, 07 October 2011 - 01:34 PM.
#19
Posted 13 October 2011 - 07:41 PM
I am having the problem described here, so I have been stepping through the advice given. I found the checkbox for hidden files, changed the permissions for the two .htaccess files, selected password protect from within filemanager and then got the same error message as ShallonCimelus. Only when I put in the same password I was no longer able to access the Administration Tool. I followed the instructions to delete the one and modify the other .htaccess file, which resulted in the original message.
I'm going around in circles and getting frustrated.
Before I found the checkbox for hidden files, I found a password protect thingy on the control panel and used it to password protect the admin directory. Although it doesn't seem to be working, there doesn't appear to be a way to unpassword protect the admin directory. Could it be preventing me from doing it the .htaccess way?
Should I delete the admin directory and reupload it from my local drive to try again, or is there something very simple and obvious that I am overlooking?
Joe
#20
Posted 14 October 2011 - 11:52 AM
I was able to solve my problem.
The information I needed was in Jim Keebaugh's post. First I figured out how to unpassword protect the admin from cpanel. Then I changed the permissions on both the .htaccess files and the admin directory. Then I used the security feature in Admin. This time there was a checkbox along with the request for a "new" password. I supplied the same username and password and checked the checkbox. It worked.
There are so many seemingly insignificant ways one can get things wrong while trying to get them right. The process for undoing password protection is an example. I watched the instructional video supplied by cpanel that showed the process for creating password protection. It didn't show how to undo it, so first I tried undoing it in the same sequence as doing it. That didn't work. But when I tried undoing it in reverse sequence, it did work!
There seem to be two competing methods for password protecting the admin. One calls for using cpanel, one for using admin. It can be tricky figuring out which method is right, and even more tricky to back out of the method that is wrong. Knowing that I needed to use the same password, not a new one, and that I had to change the permissions for the admin directory as well as for the .htaccess files was key, at least for me.
Joe









