Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / NewStats: 3,207,676 members, 7,999,919 topics. Date: Monday, 11 November 2024 at 04:35 PM |
Nairaland Forum / Science/Technology / Webmasters / Joomla Administrator Login Removal (5659 Views)
How To Login To Wordpress Dashboard And Cpanel Using Simpleserver Or XT181 / Userpro V2.4 - User Profiles With Social Login (wordpress Premium Plugin) / I Need A Registration And Login Facility For My Website (2) (3) (4)
Joomla Administrator Login Removal by schneid: 5:48pm On Apr 07, 2011 |
Hi joomla gurus. have u idea how i can remove the joomla admnistrator log in page from the public view. i.e www.sitename.com/administrator this is one way of knowing any site deliverd with joomla and u might not want to reveal that. so what do u ? thanks |
Re: Joomla Administrator Login Removal by yawatide(f): 6:20pm On Apr 07, 2011 |
1) How many regular users will know to type "/administrator"? 2) Who cares that you are using Joomla? Is it a sin? Someone like me can tell if you are using Joomla 99% of the time simply by looking at the layout of the page and/or your urls. |
Re: Joomla Administrator Login Removal by schneid: 6:24pm On Apr 07, 2011 |
@yawa thnks but what do u suggest? |
Re: Joomla Administrator Login Removal by Slyr0x: 11:22pm On Apr 07, 2011 |
yawa-ti-de: 1.) Whats yo definition of 'regular'? Dyu know malicious users also fall into this category 2? 2.) Kiddies, haXors, 3l33t, Random Scripts Users, Real-life Enemies, Virtual Enemies. Lemme cite an example, One of the aforementioned 'regular users' visits www . exploit-db . com , searches for any "Joomla" exploit and comes across the "People Component" exploit in Joomla. .i.e. www . exploit-db . com /exploits/15989/ . The exploit says A) SQL Injection That means a simple google query i.e. inurl:/index.php?option=com_people&controller=people will bring out ALL sites using this component. Adding -1 UNION SELECT username,password,3 FROM jos_usersafter the 'id' parameter will reveal usernames & pwds. And what makes the whole 'exploitation' interesting? Finding a 'login page'! Nd for joomla, its /administrator. . .Before yhu know whats happening, u ve an intruder in yo system. .he might up a svr shell, up a Mailer, get yo customer's infos and so on. . Buh an admin usrname & pwd WITHOUT a login page is as useless as having a KEY without a door to open with. @OP, twill be nice if you can find yo way round it OR better still try asking http://www.lekeojikutu.com/(use the contact me form). .he's also a member here and he configd his well. [size=4pt]at least to some extent.[/size] |
Re: Joomla Administrator Login Removal by Slyr0x: 12:42am On Apr 08, 2011 |
Jst got released frm NL's Jail. .Chk d image attached
|
Re: Joomla Administrator Login Removal by yawatide(f): 2:54am On Apr 08, 2011 |
Leave it there. |
Re: Joomla Administrator Login Removal by free2: 12:18pm On Apr 08, 2011 |
schneid: I suggest u should install your joomla in a directory named "i or 1", or any hard to notice character. With this, your admin will only load on: www.sitename.com/i/administrator (Note the: /i/). Many regular users will never type "/i/administrator" Do not forget to redirect www.sitename.com to www.sitename.com/i if not your site will not be found by searching www.sitename.com Enjoy! |
Re: Joomla Administrator Login Removal by yawatide(f): 1:58pm On Apr 08, 2011 |
Oga slyrox, I understand where you are coming from, don't get me wrong. All websites on the net are pretty much vulnerable, when it boils down to it. Having said that, it is up to the web developer/web host to add as many layers of security on top of what may already be there so as to avoid as many loopholes as possible. I tried your script on 3 joomla sites that I know and it didn't produce the results as posted here. Not to say that it won't work on any other site(s), it didn't work on the ones I tested out. |
Re: Joomla Administrator Login Removal by schneid: 3:50pm On Apr 08, 2011 |
yawa-ti-de: okay i will try that. it seems lojik offered a solution a long time ago but i did not take note. does anyone has link to that thread? oga lojik come rescue this , |
Re: Joomla Administrator Login Removal by yawatide(f): 4:10pm On Apr 08, 2011 |
Hopefully, it is one of these, http://search.yahoo.com/search?p=lojik+joomla&fr=yscpb&vs=nairaland.com |
Re: Joomla Administrator Login Removal by schneid: 6:03pm On Apr 09, 2011 |
@yawa tanks, i was able to get this: [/quote]Re: What Cool Joomla Site(s) Have You Seen? sincerely, i dnt get all this. anyway WHY BOTHER!!!!!!!!!! thanks yawa |
Re: Joomla Administrator Login Removal by Slyr0x: 1:25am On Apr 10, 2011 |
Oga Yawa, dat exploit aint 0-day anymore reason y it ddnt work on d sited u tested 'em on. . .go thru d exploit db site nd u'll understand me. |
Re: Joomla Administrator Login Removal by Chefgray92: 6:53am On Oct 21, 2022 |
Slyr0x: Mr.slyr0x good day bruv . Please it's very important I speak with you, how do I contact you please |
(1) (Reply)
MTN Youtube Hourly Data Plan, How To Subscribe / Make Serious Money Flipping Blogs In Nigeria ( Free Guide ) / Basic SEO Tips And Guidelines For Blog In 2022 - Tuplea
(Go Up)
Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health religion celebs tv-movies music-radio literature webmasters programming techmarket Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10) Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 46 |