Results 1 to 9 of 9

Thread: Securing admin folder

  1. #1
    Join Date
    Oct 2005
    Posts
    9
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default Securing admin folder

    Hi everyone, advance apologies for any mistakes - first time poster.

    I've installed osCommerce, carefully following the tutorials mentioned elsewhere and the original docs, and applied the fixes from the previous post (PHP5 fix - BIG thanks for that to all who contributed). Everything seems fine and I can access both admin and store sections until I get around to securing the admin folder.

    I'm unable to access the store and admin sections, receiving an HTTP 500 error, after password protecting my admin folder through HELM. As soon as I remove the password protection from the admin folder through HELM, I have complete access again.

    Does this mean that I have to manually configure the .htaccess and .htpasswd files? Or have I just been a bit of a plum and done something wrong elsewhere?

  2. #2
    Join Date
    Mar 2005
    Location
    Isle of Man
    Posts
    1,261
    Thanks
    3
    Thanked 23 Times in 23 Posts

    Default

    Do you not get the Authentication pop-up in your browser when trying to view the page at all? Never had this problem myself.

    I think I'm right in saying that you can't really use .htaccess with IIS. If you have those files in the directories, maybe they are causing the problems?

  3. #3
    Join Date
    Feb 2004
    Posts
    4,877
    Thanks
    2
    Thanked 134 Times in 113 Posts

    Default

    Remember to NOT upload any osCommerce incuded .HTACESS files - they are linux based and mess up the secured folders filter.
    Warren Ashcroft
    Red Fox UK Limited - Pioneers in Internet Technology
    http://www.redfoxuk.com
    w.ashcroft [at] redfoxuk.com

    NOTE: Forum Private Messaging should not be used to contact staff with support queries.

  4. #4
    Join Date
    Oct 2005
    Posts
    9
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default Poxy proper jobs!

    Thanks for the replies, guys.

    I've removed the .htaccess files and secured the admin folder via HELM and I can still access the store and admin so that's a step up but I still don't have a secure admin folder - I can go straight to it with no password request. I suspect that I need to reinstall osCommerce (remembering to leave the .htaccess files at home) so I'll get stuck in when I get back from work.

    Thanks again, I'll post how it goes.

  5. #5
    Join Date
    Feb 2004
    Posts
    4,877
    Thanks
    2
    Thanked 134 Times in 113 Posts

    Default

    Quote Originally Posted by Al@iamstudios
    Thanks for the replies, guys.

    I've removed the .htaccess files and secured the admin folder via HELM and I can still access the store and admin so that's a step up but I still don't have a secure admin folder - I can go straight to it with no password request. I suspect that I need to reinstall osCommerce (remembering to leave the .htaccess files at home) so I'll get stuck in when I get back from work.

    Thanks again, I'll post how it goes.
    Find and delete all .htaccess files, then simply reinstalled and resetup the secured folders in Helm.
    Warren Ashcroft
    Red Fox UK Limited - Pioneers in Internet Technology
    http://www.redfoxuk.com
    w.ashcroft [at] redfoxuk.com

    NOTE: Forum Private Messaging should not be used to contact staff with support queries.

  6. #6
    Join Date
    Oct 2005
    Posts
    9
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default Result!

    All working beautifully!

    I deleted all osCommerce files from the server and reinstalled it. The .htaccess files never even got a sniff of the web this time though and after completing the installation/configuration, I now have a fully secure admin folder. As a matter of fact, it's even cleared up some other errors I was getting in the store with missing parameters.

    Thanks again Nick & Warren - much appreciated.

    Just out of curiosity, I guess that when the osCommerce docs mention additions to the Directory Index ("Add to your DirectoryIndex statement and include the following : index.php This can be done in the Apache httpd.conf file if you have root access, or can be done in an .htaccess file in your /catalog dir"), it can be ignored?

  7. #7
    Join Date
    Mar 2005
    Location
    Isle of Man
    Posts
    1,261
    Thanks
    3
    Thanked 23 Times in 23 Posts

    Default

    I think you can safely ignore that. the server is set up to use index.php as one of the defaults anyway.

  8. #8
    Join Date
    Oct 2005
    Posts
    9
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    Sweet. Thanks for that.

    Just for reference, I used these docs for the install...
    http://oscdox.com/phpWiki.html

  9. #9
    Join Date
    Mar 2005
    Location
    Isle of Man
    Posts
    1,261
    Thanks
    3
    Thanked 23 Times in 23 Posts

    Default

    Quote Originally Posted by Al@iamstudios
    Sweet. Thanks for that.
    No Problem.
    (I've always wanted to say that!)

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Securing None Asp.Net content
    By Spire in forum ASP.NET
    Replies: 6
    Last Post: 11th April 2006, 05:20 PM
  2. Placement of FTP folder
    By Fruitbat in forum General Technical Support
    Replies: 3
    Last Post: 11th February 2006, 08:26 PM
  3. File/Folder synchronisation ...
    By RMPnet in forum General Technical Support
    Replies: 7
    Last Post: 4th November 2005, 10:08 AM
  4. Can you set adomain to a alias folder?
    By dv8host in forum Technical Support
    Replies: 3
    Last Post: 30th August 2005, 03:20 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •