Thread: Admin Passwords

Results 1 to 5 of 5
  1. #1
    Join Date
    Mar 2010
    Posts
    77
    Plugin Contributions
    0

    Default Admin Passwords

    I'm getting really fed-up of not being able to rotate my admins passwords, I have 4 websites with 3 passwords which I rotate. Why does Zencart not allow me to re-use previously used passwords on a 9 month rotation?

    Someone please tell me how I can remove the "database" of previously used passwords. This level of restriction is ridiculous


    Version 1.5.0

    Thanks

  2. #2
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: Admin Passwords

    Quote Originally Posted by TonyB6 View Post
    Why does Zencart not allow me to re-use previously used passwords on a 9 month rotation?
    That's not a Zencart rule. That's imposed by Visa/Mastercard security standards. https://www.pcisecuritystandards.org/
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Jan 2007
    Location
    Australia
    Posts
    6,167
    Plugin Contributions
    7

    Default Re: Admin Passwords

    Quote Originally Posted by TonyB6 View Post
    Someone please tell me how I can remove the "database" of previously used passwords. This level of restriction is ridiculous
    If you insist. Running this SQL command should do it
    UPDATE `admin` SET `prev_pass1`= NULL,`prev_pass2`= NULL,`prev_pass3`= NULL WHERE 1;

    As DrByte has suggested though, in doing this the store will no longer be PCI compliant and you must not process CC payments on the site.

    If you don't wish a forced password change every 90 days set the 'last_modified' field to some time in the distant future.

    PCI compliancy aside, I neither recommend or condone these changes. The 'rules' were developed from basic good security practices. Ignore them at your own risk.

    Cheers
    Rod

  4. #4
    Join Date
    Jan 2004
    Location
    N of San Antonio TX
    Posts
    9,682
    Plugin Contributions
    11

    Default Re: Admin Passwords

    I think this was one of the few times that an answer in PM would have been better advised.

    Just sayin'
    A little help with colors.
    myZenCartHost.com - Zen Cart Certified, PCI Compatible Hosting by JEANDRET
    Free SSL & Domain with semi-annual and longer hosting. Updating 1.5.2 and Up.

  5. #5
    Join Date
    Jan 2007
    Location
    Australia
    Posts
    6,167
    Plugin Contributions
    7

    Default Re: Admin Passwords

    Quote Originally Posted by dbltoe View Post
    I think this was one of the few times that an answer in PM would have been better advised.

    Just sayin'
    Wouldn't matter. The NSA would have gotten to see it anyway. :)

    Cheers
    Rod

 

 

Similar Threads

  1. v153 How to convert bunch of text passwords to ZC-format passwords?
    By oavs in forum General Questions
    Replies: 3
    Last Post: 24 Sep 2014, 01:50 AM
  2. v151 One of my changed Admin passwords does not log-in
    By marton_1 in forum Customization from the Admin
    Replies: 4
    Last Post: 4 Sep 2014, 04:42 PM
  3. v139h Retreiving lost admin passwords
    By thestampnomad in forum General Questions
    Replies: 1
    Last Post: 8 May 2014, 03:51 AM
  4. v150 Problems with my Admin passwords
    By arrow in forum Upgrading to 1.5.x
    Replies: 0
    Last Post: 20 Jul 2012, 02:20 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg