Author Topic: How do you PROTECT files ** Stop anyone going on ADMIN  (Read 9581 times)

0 Members and 1 Guest are viewing this topic.

Offline zakaria666

  • Full Member
  • ***
  • Posts: 211
    • View Profile
How do you PROTECT files ** Stop anyone going on ADMIN
« on: July 19, 2010, 10:42:48 PM »
Hello

I want to know if there is any way of stopping another user from typing http://www.mysite.com/4images/admin

and then getting the admin screen. ??

Thanks alot

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #1 on: July 19, 2010, 10:52:44 PM »
There is no reason restrict users from accessing that page, because without proper administrator username/password they wont go further login screen.
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline zakaria666

  • Full Member
  • ***
  • Posts: 211
    • View Profile
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #2 on: July 19, 2010, 11:39:31 PM »
Thank you sir for your prompt reply

You are correct but the problem is, the website i have is garunteed to experience alot of hacks garunteed. I promise you that, and there are amazingly smart people out there who will not stop until they succeed, hence why i want to protect the admin folder and any other part i believe may be vulnerable. :-( its messed up that i actually have to do this but i have protect myself from loosers out there who will without a doubt not sleep until my website is hacked. And like i said, i know a fact it will come to that.

any advice sir??

thank you

Offline Nicky

  • Administrator
  • 4images Guru
  • *****
  • Posts: 3.195
    • View Profile
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #3 on: July 20, 2010, 12:30:29 AM »
cheers
Nicky
Your first three "must do" before you ask a question ! (© by V@no)
- please read the Forum Rules ...
- please study the FAQ ...
- please try to Search for your answer ...

nicky.net 4 4images
Signature stolen from mawenzi

Offline zakaria666

  • Full Member
  • ***
  • Posts: 211
    • View Profile
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #4 on: July 20, 2010, 02:07:30 AM »
Thank you so much for your reply,

Please forgive me as i am a novice to this. I dont think i have a htapsswrd on my server...

Please do forgive me, Can you break it down to me in exactly what i do step by step as the site you gave me presumes i know what i am suppose to do but i have no idea. im so sorry sir do forgive me for asking alot of quesitons. But what sort of files should i protect with this, obviously i cannot do the whole site other noone could be allowed in but the admin area for one but how.

god bless u sir and all the other employees of 4images for there proffesionalism

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #5 on: July 20, 2010, 07:44:07 AM »
Step-by-step is well explained on that site. Just try it.
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline zakaria666

  • Full Member
  • ***
  • Posts: 211
    • View Profile
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #6 on: July 20, 2010, 10:51:10 PM »
Hello sir,

I wondered would it cause an issue if i changed the folder admin name, to for example (secret), so instead of www.example.com/4images/admin   

its

www.example.com/4images/secret????

thank you

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #7 on: July 21, 2010, 02:22:01 AM »
Nothing will work if you do that. /admin/ path is hard coded into 4images.

You can always restrict that directory to specific IP addresses (though it wont work if your IP is dynamic)
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline zakaria666

  • Full Member
  • ***
  • Posts: 211
    • View Profile
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #8 on: July 21, 2010, 08:30:55 PM »
Internal Server Error
The server encountered an internal error or misconfiguration and was unable to complete your request.

Please contact the server administrator, webmaster@globalkurd.com and inform them of the time the error occurred, and anything you might have done that may have caused the error.

More information about this error may be available in the server error log.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.



________________

The above is teh error i am getting using what you have told me to use, it doesnt seemto work :-( im screwed

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #9 on: July 21, 2010, 08:37:41 PM »
you'll need server's error logs in order to learn what went wrong and how to fix it.
Any way, If someone be able hack your 4images, sure enough they will be able hack this kind of protection even easier, so IMO you are wasting your time with this.
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline zakaria666

  • Full Member
  • ***
  • Posts: 211
    • View Profile
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #10 on: July 21, 2010, 10:20:39 PM »
I guess your right  

But please dont say it like that   i bought from you guys with confidence it was hack proof. I mean the least i can do is give the loosers a hard enough time to hack it and not make it easy on them. Apart from the hacks in the past via the plugins (wordpress) has there been any other incidents where there have been hacks that people have told u about?

 

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #11 on: July 22, 2010, 12:29:37 AM »
The only incidents possible if 4images not patched or if a security hole newly discovered and unknown to us (yet)
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)

Offline zakaria666

  • Full Member
  • ***
  • Posts: 211
    • View Profile
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #12 on: July 23, 2010, 04:18:25 PM »
Does your software offer any brute force protection or time outs sir??

also i dont know if i may have offended you or up set you but you havent replied sir to this topic. Please forgive me if i have and i sincerely apologize

Topic: ** How do you add categories to user groups???? 

Offline V@no

  • If you don't tell me what to do, I won't tell you where you should go :)
  • Global Moderator
  • 4images Guru
  • *****
  • Posts: 17.849
  • mmm PHP...
    • View Profile
    • 4images MODs Demo
Re: How do you PROTECT files ** Stop anyone going on ADMIN
« Reply #13 on: July 24, 2010, 01:09:47 AM »
By default 4images doesn't provide any such protection as it's just a gallery and not online banking site...But with enough PHP knowledge such protection could be implemented.

As of being offended - not at all, just answering only when have free time ;)
Your first three "must do" before you ask a question:
Please do not PM me asking for help unless you've been specifically asked to do so. Such PMs will be deleted without answer. (forum rule #6)
Extension for Firefox/Thunderbird: Master Password+    Back/Forward History Tweaks (restartless)    Cookies Manager+    Fit Images (restartless for Thunderbird)