Security problem - Illegal admin activities

Bug Reporting and Feature Suggestions /Improvements go here.

Moderator: pgolovko

Security problem - Illegal admin activities

Postby Tibor » 11/09/2009 8:25 am

A friend of mine builds now another ADP catalogue. We both placed an hxxp://.../admin/index.php?adp=links&action=approve link to each site, for a more comfortable access of link approval.

Amd now the Easter Egg: When we both had a live administration session, I was able to enter his link approval page, and I was able to edit, modify, move and approve the links in his queue! Nice help among ADP Admins on the World :P

I don't know, how does it work (cookie with no session id?), but it was funny... May I ask you for some advice, how to fix this bug?
Addendum: It seems, that reverse it does not work! My copy is safe! And My friend's colleague from other PC, but same IP could also enter - withaout any earlier ADP activities.
Tibor
 
Posts: 9
Joined: 10/23/2009 1:00 am


Re: Security problem - Illegal admin activities

Postby gc_rjauregui » 11/09/2009 2:57 pm

So you are saying that the ADP installs are on different domains, but if you authenticate to install A, you can also access install B without having to authenticate?
Best Regards,

Ryan Jauregui
geekcoders development member

laf innovative | development blog
User avatar
gc_rjauregui
Site Admin
 
Posts: 394
Joined: 03/25/2006 1:23 am
Location: Stanton, CA

Re: Security problem - Illegal admin activities

Postby Tibor » 11/11/2009 6:34 am

Yes, exactly. And it happened, when admins were active on both server. Meanwhile Admin of Install B could not reach Install B. Is it possible, that it is a webserver configuration problem and nothing to do with ADP?

(Sorry for late reaction, I did not checkedin notify option.)
Tibor
 
Posts: 9
Joined: 10/23/2009 1:00 am

Re: Security problem - Illegal admin activities

Postby gc_rjauregui » 11/11/2009 9:39 am

I am going to say it has something to do with the web server, since the authentication is handled via .htaccess and not via ADP.
Best Regards,

Ryan Jauregui
geekcoders development member

laf innovative | development blog
User avatar
gc_rjauregui
Site Admin
 
Posts: 394
Joined: 03/25/2006 1:23 am
Location: Stanton, CA

Re: Security problem - Illegal admin activities

Postby Tibor » 11/11/2009 10:18 am

Thx Ryan, after the first surprise I agree with you.
Tibor
 
Posts: 9
Joined: 10/23/2009 1:00 am


Return to Bug Reporting

Who is online

Users browsing this forum: No registered users and 0 guests

cron