- Posts: 4
- Thank you received: 0
Securtiy Issue
- pjaallan
- Topic Author
- Offline
- New Member
Less
More
11 years 7 months ago - 11 years 7 months ago #1492
by pjaallan
Securtiy Issue was created by pjaallan
This extension looks promising but there is potential security issue. We use Akeeba Admin Tools to help secure our site which includes password protecting the Administrator folder. The zhGoogle Map plugin seems to be accessing something in this directory as when the plugin is enabled the website displays a logon box to everyone.
For this reason we cannot use your extension. I have attached a screen shot of a post explaining the problem. Do you have any way of fixing your cpde.
Thank you
www.akeebabackup.com/documentation/troub...ooter/atadminpw.html
Text from Akeeba article below.
I enabled this feature and now the front-end of my site asks me for a username and password?!
This is not a bug in Admin Tools, but a problem with one of the extensions (components, modules or plugins) you are using.
More specifically, Joomla! extensions are not supposed to load anything from the administrator area of your site in the front-end. However, some badly written extensions try to access static media files (CSS, Javascript, images) from directories inside the administrator directory. On notorious example is the Zoo CCK extension. Since all of the contents of your administrator directory are protected with a username/password, your browser will prompt you for one as soon as it is instructed to download a file from that protected directory or any of its subdirectories.
There are two workarounds:
Disable the administrator password protection. This degrades your site's security but is the easiest and most immediate change.
Consult the developer of the offending extension and explain to him that loading files from the administrator area of the component in the front-end of the site is insecure and he has to resolve this issue. Hopefully, developers will realize that this practice is unsafe and fix their software.
For this reason we cannot use your extension. I have attached a screen shot of a post explaining the problem. Do you have any way of fixing your cpde.
Thank you
www.akeebabackup.com/documentation/troub...ooter/atadminpw.html
Text from Akeeba article below.
I enabled this feature and now the front-end of my site asks me for a username and password?!
This is not a bug in Admin Tools, but a problem with one of the extensions (components, modules or plugins) you are using.
More specifically, Joomla! extensions are not supposed to load anything from the administrator area of your site in the front-end. However, some badly written extensions try to access static media files (CSS, Javascript, images) from directories inside the administrator directory. On notorious example is the Zoo CCK extension. Since all of the contents of your administrator directory are protected with a username/password, your browser will prompt you for one as soon as it is instructed to download a file from that protected directory or any of its subdirectories.
There are two workarounds:
Disable the administrator password protection. This degrades your site's security but is the easiest and most immediate change.
Consult the developer of the offending extension and explain to him that loading files from the administrator area of the component in the front-end of the site is insecure and he has to resolve this issue. Hopefully, developers will realize that this practice is unsafe and fix their software.
Last edit: 11 years 7 months ago by pjaallan.
Please Log in or Create an account to join the conversation.
- Dima
- Offline
- Platinum Member
11 years 7 months ago #1493
by Dima
Don't forget support my developments: post review in JED , donate , help with translation
Replied by Dima on topic Securtiy Issue
Hi. Do you read my docs
wiki.zhuk.cc/index.php?title=Zh_GoogleMa...en_map_is_displaying
wiki.zhuk.cc/index.php?title=Zh_GoogleMa...ibilityModeRSFAnchor
wiki.zhuk.cc/index.php?title=Zh_GoogleMa...en_map_is_displaying
wiki.zhuk.cc/index.php?title=Zh_GoogleMa...ibilityModeRSFAnchor
Don't forget support my developments: post review in JED , donate , help with translation
Please Log in or Create an account to join the conversation.
- pjaallan
- Topic Author
- Offline
- New Member
Less
More
- Posts: 4
- Thank you received: 0
11 years 7 months ago #1494
by pjaallan
Replied by pjaallan on topic Securtiy Issue
Thank you for that info, i didn't see that bit
Please Log in or Create an account to join the conversation.
Time to create page: 0.199 seconds