Securtiy Issue

  • pjaallan
  • Topic Author
  • Offline
  • New Member
  • New Member
More
11 years 7 months ago - 11 years 7 months ago #1492 by pjaallan
Securtiy Issue was created by pjaallan
This extension looks promising but there is potential security issue. We use Akeeba Admin Tools to help secure our site which includes password protecting the Administrator folder. The zhGoogle Map plugin seems to be accessing something in this directory as when the plugin is enabled the website displays a logon box to everyone.

For this reason we cannot use your extension. I have attached a screen shot of a post explaining the problem. Do you have any way of fixing your cpde.

Thank you

www.akeebabackup.com/documentation/troub...ooter/atadminpw.html

Text from Akeeba article below.

I enabled this feature and now the front-end of my site asks me for a username and password?!

This is not a bug in Admin Tools, but a problem with one of the extensions (components, modules or plugins) you are using.

More specifically, Joomla! extensions are not supposed to load anything from the administrator area of your site in the front-end. However, some badly written extensions try to access static media files (CSS, Javascript, images) from directories inside the administrator directory. On notorious example is the Zoo CCK extension. Since all of the contents of your administrator directory are protected with a username/password, your browser will prompt you for one as soon as it is instructed to download a file from that protected directory or any of its subdirectories.

There are two workarounds:

Disable the administrator password protection. This degrades your site's security but is the easiest and most immediate change.

Consult the developer of the offending extension and explain to him that loading files from the administrator area of the component in the front-end of the site is insecure and he has to resolve this issue. Hopefully, developers will realize that this practice is unsafe and fix their software.
Last edit: 11 years 7 months ago by pjaallan.

Please Log in or Create an account to join the conversation.

More
11 years 7 months ago #1493 by Dima

Please Log in or Create an account to join the conversation.

  • pjaallan
  • Topic Author
  • Offline
  • New Member
  • New Member
More
11 years 7 months ago #1494 by pjaallan
Replied by pjaallan on topic Securtiy Issue
Thank you for that info, i didn't see that bit

Please Log in or Create an account to join the conversation.

Time to create page: 0.199 seconds
Powered by Kunena Forum