Page 2 of 2 FirstFirst 12
Results 11 to 19 of 19
  1. #11
    Join Date
    Sep 2014
    Location
    Buffalo, New York, United States
    Posts
    10
    Plugin Contributions
    0

    Default Re: Cannot access admin area - login loops back to admin login page

    oh no! I did not have that email in there. like i said, i haven't touched anything except adding products and such. haven't found any changed or new files as of yet. any other thoughts while i keep looking?

  2. #12
    Join Date
    Sep 2014
    Location
    Buffalo, New York, United States
    Posts
    10
    Plugin Contributions
    0

    Default Re: Cannot access admin area - login loops back to admin login page

    and it is exactly the same error as the k1ra posted.

  3. #13
    Join Date
    Sep 2014
    Location
    Buffalo, New York, United States
    Posts
    10
    Plugin Contributions
    0

    Default Re: Cannot access admin area - login loops back to admin login page

    If i use an incorrect username, i get the error message, so it is hitting the db

  4. #14
    Join Date
    Sep 2014
    Location
    Buffalo, New York, United States
    Posts
    10
    Plugin Contributions
    0

    Default Re: Cannot access admin area - login loops back to admin login page

    went into the admin table, the email was changed there to admin@localhost and the lockout_expires was set to 1418521640. i changed both and was able to login. i then changed the login and password for the admin. i am now looking at my files for something out of the ordinary. also, some ip from Denver logged in before I experienced the problem today. looks like they reached the admin but no other logs were listed.

  5. #15
    Join Date
    Jan 2004
    Posts
    65,255
    Blog Entries
    7
    Plugin Contributions
    226

    Default Re: Cannot access admin area - login loops back to admin login page

    Here's what's happening on a technical level:

    Whenever someone tries to log into your admin multiple times without the correct password, the system emails that admin user and the primary administrator about the failure.
    If the email address is invalid, the kind of error you've quoted will be seen in the logs.

    So, the presence of the error suggests 2 things are both happening to you:
    a) someone's trying to login to your admin and doesn't have a valid username+password. You should do something about that.
    b) you've got an admin user whose email address is "admin@localhost", which is a default user account, and should be deleted, as long as you've got a different admin account you can use

    If you cannot log into your own admin account, then the above symptoms combined with your inability to log in is further reason to suggest your site has been compromised.
    You should immediately do a thorough site inspection and do all necessary cleanup to be certain you've prevented them from doing any further damage or getting back in again: http://www.zen-cart.com/wiki/index.p...ing_From_Hacks

    And to give yourself access to your admin account again, the following may be necessary: http://www.zen-cart.com/content.php?...admin-password (and whoever compromised your site might have been attempting to do this very thing, which could explain how the "admin@localhost" user got created and also why your old login stopped working ... but if they gained access to do that, then you need to find out HOW else they'll be back again)
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  6. #16
    Join Date
    Sep 2014
    Location
    Buffalo, New York, United States
    Posts
    10
    Plugin Contributions
    0

    Default Re: Cannot access admin area - login loops back to admin login page

    There is no user with the admin@localhost email. i only had one and that was mine. i show the rogue login only 4 times but never made it to the admin user page. I have no idea how that was changed as well as the very large lockout number. the many incorrect logins must have been me. anyway i went into the db and was able to change the email and lockout and get back in. I have changed the login and password(harder) and made another superuser just in case. I will now try and find any unusual files and keep an eye out. My question is, can you log into the admin with the admin@localhost still in there as long as the uname and password were always entered correctly? I only ask as we paid someone to upgrade this site to 1.5 over year ago and maybe we never even changed it? I just changed my password yesterday, and had the old and new saved in firefox. so every time I logged in, it was wrong the first time and then the second attempt was correct. i have since deleted the old saved password. I guess what I am saying is....am I the one who triggered the lockout? I find it ironic that the password was changed yesterday and today it was locked out!

  7. #17
    Join Date
    Jan 2004
    Posts
    65,255
    Blog Entries
    7
    Plugin Contributions
    226

    Default Re: Cannot access admin area - login loops back to admin login page

    Quote Originally Posted by Peter Cefalu View Post
    My question is, can you log into the admin with the admin@localhost still in there as long as the uname and password were always entered correctly? I only ask as we paid someone to upgrade this site to 1.5 over year ago and maybe we never even changed it?
    Yes.

    Quote Originally Posted by Peter Cefalu View Post
    I just changed my password yesterday, and had the old and new saved in firefox. so every time I logged in, it was wrong the first time and then the second attempt was correct. i have since deleted the old saved password. I guess what I am saying is....am I the one who triggered the lockout? I find it ironic that the password was changed yesterday and today it was locked out!
    Yes, it seems like it was your own Firefox that locked you out.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  8. #18
    Join Date
    Sep 2014
    Location
    Buffalo, New York, United States
    Posts
    10
    Plugin Contributions
    0

    Default Re: Cannot access admin area - login loops back to admin login page

    Thank you for responding DrByte. I was in full panic mode! I still do not know about that ip from Denver but the original poster had the exact same error. I have reached out to them in hopes of getting more info. Anyway, I am going through all the files anyway(nothing yet) and changing passwords. We used dedicated ssl and i think we are safe but you never know. I spoke with my hosting company and they saw nothing as well. Again, thank you for the help.

  9. #19
    Join Date
    Sep 2014
    Location
    Buffalo, New York, United States
    Posts
    10
    Plugin Contributions
    0

    Default Re: Cannot access admin area - login loops back to admin login page

    Just to finish this thread, the denver ip is my host, the logins were from the support guy there. no hack, just an odd situation with the failed login attempts. Be sure to change all the emails after setup!

 

 
Page 2 of 2 FirstFirst 12

Similar Threads

  1. v153 Can't login to admin - loops back to login
    By missyenta in forum Basic Configuration
    Replies: 24
    Last Post: 17 Mar 2016, 10:31 PM
  2. Replies: 2
    Last Post: 3 May 2013, 02:49 AM
  3. admin login page is missing. cant access admin area
    By ztotheetothen in forum Customization from the Admin
    Replies: 11
    Last Post: 26 Feb 2011, 05:44 PM
  4. Cannot access Admin login page
    By peter49 in forum Installing on a Windows Server
    Replies: 1
    Last Post: 22 Mar 2010, 11:26 PM
  5. Admin Login Page Loops forever
    By ehdesign in forum General Questions
    Replies: 12
    Last Post: 2 Apr 2008, 02:58 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR