New Zenner
- Join Date:
- Oct 2008
- Posts:
- 24
- Plugin Contributions:
- 0
ckeditor - does it upload images
Does CKEDITOR allow you to upload images to your server?
Thanks
Views: 11,775
New Zenner
Does CKEDITOR allow you to upload images to your server?
Thanks
Sensei
Not natively, no.
New Zenner
Thank you for that prompt rely:)
Zen Follower
There is a CKFinder file manager, but haven't had luck integrating with CKEditor...:blink:
Totally Zenned
It's not easy to integrate Image Manager extensions to WYSIWYG editors such as CKEditor or TinyMCE.
If you don't integrate them securely, you leave yourself open to the upload of malicious files by hackers.
But integrating them securely is very difficult too as Zen Cart is deliberately locked down to not offer third-party apps a way to penetrate its security, since these would offer a point of attack for hackers.
Zen Follower
Hi kuroi,
First, I would like to say thanks for the contrib! As you read in my other post, It installed and works flawlessly, including the upgrade process. CKEditor is a nice addition for Zen users.
I do understand the potential security issues with file managers. However, if one does wish to configure CKFinder, would you happen to have any helpful directions on this? :smile:
Zen Follower
OK, got ckfinder working on localhost!
Now I am trying to secure it. In the ckfinder config.php file, there is a CheckAuthentication() function that needs to return true. I added the following, but doesn't seem to work. :blink:
return isset($_SESSION['securityToken']) && $_SESSION['securityToken'];
This should return true if admin is logged in...correct?
Any ideas?
Totally Zenned
Alas that won't work as the page has already been completely rendered by the time you initiate the CKFinder call, and the session has been closed down to protect the information that it contains.
Nor can you restart the same session at this point, since the http headers were sent prior to the page rendering.
If you're working from a fixed IP you might be able to check that the browser request came from that IP and exclude any others.
You can also obscure the location of the editors (similarly to changing the name of the admin folder) by renaming the folder and editing the DIR_WS_EDITOR setting in the admin ckeditor.php file, which would make it more difficult for a hacker to find and access the CKFinder upload facility.
Zen Follower
Thanks for the info about Zen sessions kuroi.
I had tried several methods, but as you pointed out, Zen sessions by design, are very secure...
I like the idea of obscuring the dir and looking at the IP...
Would there be any other way to validate that one is logged in to the store admin that can be made available to the ckfinder config script?
Totally Zenned
Alas, the information used to verify that somebody is logged in is in the session that you can't get at.
Zen Follower
Got it!
So, other then the suggested IP restriction and editors dir name change, any other validation suggestion one could do to verify that ckfinder is not being hacked?
Also, my ckeditor.php file doesn't have a DIR_WS_EDITOR setting. I guess I need to code this?
Thanks again! :clap:
Zen Follower
I stumbled across this thread when I had to secure CKFinder in Zen Cart. The IP address restriction didn't work for me, as my client is on a variable IP.
So I slapped a cPanel folder protection on and this should do the trick. It asks for the log in as soon as you access a page in admin which has CKFinder embeded and also if you try to access CKFinder directly.
Maybe this helps others who come across this thread.
All the best, Edith
Zen Follower
OK, don't mean to beat a horse as they say...
I have CKEditor and CKFinder installed and working on 1.3.9d. I want to secure (as best as possible) CKFinder.
Here's what I have so far in general:
I read in another thread to pwd the editor and finder dir as well. Any thought on this redundancy?
Since I don't know the methods a hacker could use to get in and use CKFinder, any other suggestions / recommendation (other then don't use CKFinder) would be helpful to all of us that need / wish to use CKFinder.
Thanks :D
Totally Zenned
kwright:
I want to secure (as best as possible) CKFinder.
I had FCKeditor(with image uploader) installed on all my 1.3.8 sites and just changed the admin url, and I was never hacked.
If you change your admin url this should protect your site.
I looked for CKFinder in the free ad-ons... pity no one has added it for zencart.
p.s.
without changing the admin url your site is vulnerable I think.
Totally Zenned
vandiermen:
I looked for CKFinder in the free ad-ons... pity no one has added it for zencart.It can't be added for Zen Cart. It's a commercial product requiring a paid-for license.
Totally Zenned
kuroi:
It can't be added for Zen Cart. It's a commercial product requiring a paid-for license.
It seems you can download it for free for your own websites. Perhaps zencart integration patch files could be added I am not sure. Thanks for your answer.
Totally Zenned
p.s.
if you got some reseller licence from CKSource, and sold the module for zencart on your website; I would buy it. :-)
Zen Follower
vandiermen:
I had FCKeditor(with image uploader) installed on all my 1.3.8 sites and just changed the admin url, and I was never hacked.
If you change your admin url this should protect your site.
I looked for CKFinder in the free ad-ons... pity no one has added it for zencart.
p.s.
without changing the admin url your site is vulnerable I think.
Yup, done that! Even changed the editor & CKFinder dir name...I just feel there is something else I should do that would better authenticate if an admin user is "Logged-in" within the CKFinder config.php CheckAuthentication function :flex:
Totally Zenned
@vandierman The CKFinder people don't offer a reseller license. They have an OEM license, but it's not compatible with the GPL under which Zen Cart is released.
@kwright I believe that this can be done, but would require relocating the entire editor structure into the Admin to gain access to the admin session.
New Zenner
Don't know if anyone cares anymore but here is the solution I came up with for CKFinder security. Basically it limits access to the IP address of the logged in admin - it's not perfect but it's pretty good.
I establish the access to CKFinder in #admin#/includes/ckeditor.php but I'm sure this idea could be ported.
In ckeditor.php I added the following:
if (!defined('IS_ADMIN_FLAG')) {
die('Illegal Access');
}
/* BEGIN ADD */
$IP = $HTTP_SERVER_VARS["HTTP_X_FORWARDED_FOR"];
$currentcode = md5('salt_one' . $IP . 'salt_two');
/* END ADD */
$var = zen_get_languages();
The "salt_one" and "salt_two" are hardcoded random strings.
Then I added the access lines to the CKEDITOR.replace call like so
CKEDITOR.replace($(this).attr('name'),
{
coreStyles_underline : { element : 'u' },
width : 760,
language: lang[index],
filebrowserBrowseUrl: '../<?php echo DIR_WS_EDITORS ?>ckfinder/ckfinder.html?lcsd=<?php echo $currentcode ?>',
filebrowserImageBrowseUrl: '../<?php echo DIR_WS_EDITORS ?>ckfinder/ckfinder.html?type=Images&lcsd=<?php echo $currentcode ?>',
filebrowserUploadUrl:
'../<?php echo DIR_WS_EDITORS ?>ckfinder/core/connector/php/connector.php?command=QuickUpload&type=Files&lcsd=<?php echo $currentcode ?>',
filebrowserImageUploadUrl:
'../<?php echo DIR_WS_EDITORS ?>ckfinder/core/connector/php/connector.php?command=QuickUpload&type=Images&lcsd=<?php echo $currentcode ?>'
});
Now I have a parameter being passed to the CKFinder that is unique to the current users IP address (proxies, etc notwithstanding).
Then, over in the /ckfinder/config.php I test for this new parameter:
function CheckAuthentication()
{
$IP = $HTTP_SERVER_VARS["HTTP_X_FORWARDED_FOR"];
$currentcode = md5('salt_one' . $IP . 'salt_two');
$testcode = '';
if (isset($_REQUEST['lcsd'])) {
$testcode = $_REQUEST['lcsd'];
};
return ($testcode == $currentcode);
}
Perhaps I'm missing something obvious, but so far it appears to be working.
Tony
Tell staff why this post should be reviewed.