Zen Cart Logo
Forums / Installing on a Windows Server / IIS - Zen - Annonymous Access

IIS - Zen - Annonymous Access

Locked

Views: 1,114

Results 1 to 2 of 2
This thread is locked. New replies are disabled.
2 Mar 2008, 7:23 AM
#1
tabletopbmx avatar

tabletopbmx

New Zenner

Join Date:
Mar 2008
Posts:
8
Plugin Contributions:
0

IIS - Zen - Annonymous Access

Well, I have ZC installed on an IIS server. Shared. I am in the process of increasing the security of the system. I have a tip and a question...

Tip - I moved my admin directory. Then, what I did was I went into my hosting control panel and disabled anonymous access over http and ssl. Now, I only access the admin functions over SSL and it requires your IIS admin username / PW. This is somewhat of a help. I think this is probably a good thing. Once you are on, however, the pages go back to http. But, at least you are logging on using https.

Question - are there any other directories I can deny anonymous access to in the zen file structure?

Question - can anyone point me to a FAQ that is specifically for securing Zen on an IIS server? I want to lock my shop down as best as possible. I am only doing paypal/checks/MOs as payment options. But, I would still like to make sure that the board is as safe as possible.

Thanks!

2 Mar 2008, 8:34 AM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: IIS - Zen - Annonymous Access

The "anonymous access" restrictions you talk about are akin to the file-access restrictions in the supplied .htaccess files which apache honors.
Granted, you don't want to go moving all folders around or you'll end up with trouble.

The admin area also uses the editors folder, which you could secure similarly as you described.

The existing security guide can be used with relatively equal application to your situation, making adjustments as appropriate for your server:
https://www.zen-cart.com/tutorials/index.php?article=73