Important: This page is using cookies (cookies). Using this website without turning off cookies in browser, means that you agree for using it.
Buy Now! Features Downloads

Earn with us!

If you would like to start earning money with vBET join to Affiliate Program.
Results 1 to 2 of 2

Thread: Security Issue with admincp links

  1. #1
    Senior Member
    Join Date
    Nov 2009
    Posts
    168

    Default Security Issue with admincp links

    I have .htaccess protection on my admincp folder. However, when accessed it with a lang parameter in the URL (i.e. site.com/pl/admincp/) then that access is bypassed! This looks like a fairly serious security issue if it's indeed a bug.

    Also, if my forum is translated, then my admincp links include the language paremeter for some reason- they didn't before.

  2. #2
    MichaƂ Podbielski (vBET Staff) vBET's Avatar
    Join Date
    Oct 2009
    Posts
    3,037

    Default

    So add protection also for translated admincp URLs, or even better - redirect in .htaccess translated acmincp URLs to normal one. This will force going to admincp in normal way and your security will work. This is specific solution used for your forum - please adopt it to actual settings If you need help for this - please show me your actual .htaccess file.

    If you don't want to have URL tracking working for admincp just use 'Ignore URLs' option. Personally I think that it is not needed at all - when you go to admincp you do not do it from translated page, and even if, then you can manually change the URL. Anyway 'Ignore URLs' will keep any link you want out of translation tracking.

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •