Results 1 to 3 of 3
  1. #1
    Join Date
    Dec 2006
    Posts
    163
    Plugin Contributions
    1

    red flag Why Enforcing Security by Obscurity?

    So the new 1.3.9g will not let me administer my site until I rename my admin folder?

    I do not want to rename my admin folder and have it locked down so that no one can access it without knowing two separate passwords.

    This is what security is and while I can understand people might want to hide it, I have no need for this and Zencart should not be enforcing this sort of "security"

    So can one of the admins kindly point me to where the check is done so I can disable it as to repeat, I have no need for this and do not want to practice this.

    Thanks.

  2. #2
    Join Date
    Aug 2005
    Location
    Arizona
    Posts
    27,755
    Plugin Contributions
    9

    Default Re: Why is Zencart Enforcing Security by Obscurity?

    I do not want to rename my admin folder and have it locked down so that no one can access it without knowing two separate passwords.
    That is NOT what this does - - - it only uses a re-named folder for your admin so that instead of accessing with

    http: //yourdomain.com/admin

    It will be

    http: //yourdomain.com/new_name

    NO DOUBLE PASSWORDS required
    Zen-Venom Get Bitten

  3. #3
    Join Date
    Dec 2006
    Posts
    163
    Plugin Contributions
    1

    Default Re: Why is Zencart Enforcing Security by Obscurity?

    Quote Originally Posted by kobra View Post
    That is NOT what this does - - - it only uses a re-named folder for your admin so that instead of accessing with

    http: //yourdomain.com/admin

    It will be

    http: //yourdomain.com/new_name

    NO DOUBLE PASSWORDS required
    Thanks for the response.

    I understand do what it does. It wants me to change the name of my admin folder so that would be hackers would not know where it is and thus be unable to hack me.

    What I am saying is that my admin folder is secure thanks and I have no need or wish to rename it and also do not think zencart should be forcing that sort of "security" down my throat in the first place.

    This is not real security as you well know and the real security is to address the issue that they exploit as with simply renaming, if by fluke they stumble upon the name (I bet a lot of people will just add one letter to the beginning or end) then we are back at Square 1 ... again as you well know.

    In any case, I have located where the check is done and disabled it.

    Thanks again for the response.

 

 

Similar Threads

  1. Pay Pal 10002 Security error - Security header is not valid
    By flex67 in forum PayPal Express Checkout support
    Replies: 9
    Last Post: 7 Dec 2010, 08:55 PM
  2. 10002 Security error - Security header is not valid
    By cwahm in forum PayPal Website Payments Pro support
    Replies: 5
    Last Post: 29 Apr 2010, 07:32 PM
  3. 10002 Security error - Security header is not valid
    By helpme in forum Upgrading from 1.3.x to 1.3.9
    Replies: 6
    Last Post: 28 Nov 2009, 03:17 AM
  4. Why?! Why?! Why?! (IE6 causing links to disappear instead of setting color)
    By pholli4 in forum Templates, Stylesheets, Page Layout
    Replies: 1
    Last Post: 10 May 2008, 07:57 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg