
10th January 2010, 12:11
|
|
Senior Member
|
|
Join Date: Dec 2009
Posts: 139
Thanks: 45
Thanked 8 Times in 8 Posts
|
|
How to add security to ispconfig login ?
Hi there,
I have a debian with ISPconfig 3.0.1.6 installed.
I can imagine that a cracker who has the ispconfig access could do anything he wants on the server. Do you have tips to add more security to this web login ? I'm searching for something more friendly than a .htaccess (or maybe you think that's THE solution ?).
Thanks you for your advise.
|

10th January 2010, 15:33
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 31,888
Thanks: 693
Thanked 4,188 Times in 3,205 Posts
|
|
The ispconfig login is already secured against brute force attacks and uses salted password, just use a safe password.
|

10th January 2010, 16:10
|
|
Senior Member
|
|
Join Date: Dec 2009
Posts: 139
Thanks: 45
Thanked 8 Times in 8 Posts
|
|
I have good passwords, but as I can hear about you : There's nothing to do to add more security ?
I think about the script-kiddies which try some files, etc... If everybody tell me that they don't do anything more to protect the ispconfig interface, I can trust you. But, in my case, a friend of mine (co-"admin") is afraid about the security of this such software and I don't know if he's right or not and how ton convince him !
|

12th January 2010, 18:41
|
|
Member
|
|
Join Date: Dec 2009
Location: Montreal, Canada
Posts: 36
Thanks: 0
Thanked 0 Times in 0 Posts
|
|
Quote:
Originally Posted by yoplait
I have good passwords, but as I can hear about you : There's nothing to do to add more security ?
I think about the script-kiddies which try some files, etc... If everybody tell me that they don't do anything more to protect the ispconfig interface, I can trust you. But, in my case, a friend of mine (co-"admin") is afraid about the security of this such software and I don't know if he's right or not and how ton convince him ! 
|
Its not going to be any safer with a commercial software, in fact with commercial software you dont know the code, with open source you do!
Just make sure you use Strong passwords.
|

12th January 2010, 19:04
|
|
Senior Member
|
|
Join Date: Dec 2009
Posts: 139
Thanks: 45
Thanked 8 Times in 8 Posts
|
|
The comparaison was not done with commercial softwares, but now, it's more understood from me... It seems that nobody seems to put an htaccess on the ispconfig interface...
Thanks !
|

3rd February 2010, 21:37
|
|
Junior Member
|
|
Join Date: Jul 2009
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
|
|
I'm with you yoplait. After a recent experience with my current web host (and my reason for moving to a colo solution), I would love to see a hosting control panel that takes an online banking security approach to panel security. I had a VERY STRONG password, yet the offenders still managed to get in somehow. They sure didn't get the password from malware on my computer or anything like that.
Chris
|

3rd February 2010, 21:43
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 31,888
Thanks: 693
Thanked 4,188 Times in 3,205 Posts
|
|
So, which exact problem do you have with ISPConfig security? If you find a way to login to ispconfig without knowing the correct password, let me know and we will fix it. But I'am not aware of such a problem and there has be no such problem reported in ISPConfig till now.
|

3rd February 2010, 22:02
|
|
Senior Member
|
|
Join Date: Dec 2009
Posts: 139
Thanks: 45
Thanked 8 Times in 8 Posts
|
|
Hum ... just to be exact, I don't critiquize anything about ispconfig security ... I'm really not an expert in this domain : It was just for information  .
|

3rd February 2010, 23:17
|
|
Senior Member
|
|
Join Date: Jun 2006
Posts: 375
Thanks: 11
Thanked 48 Times in 40 Posts
|
|
You can always use ssl to encrypt the https traffic and as suggested use strong passwords.
|

3rd February 2010, 23:24
|
|
Senior Member
|
|
Join Date: Dec 2009
Posts: 139
Thanks: 45
Thanked 8 Times in 8 Posts
|
|
already done  .
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +2. The time now is 20:46.
|
Recent comments
18 hours 22 min ago
23 hours 21 min ago
1 day 47 min ago
1 day 1 hour ago
1 day 3 hours ago
1 day 7 hours ago
1 day 8 hours ago
1 day 10 hours ago
1 day 23 hours ago
2 days 1 hour ago