Jump to content

Fake Admin Login Page


Daniel

Recommended Posts

Ah, of course! I had wondered if I could feed it a fake password, but couldn't work out how to get the dialogue box back! Feeding it the fake details in the url is obvious when I think about it now!

 

In the meantime, I also got it working again using a different browser from the first one, which let me log-in again (or not as the case was!).

 

Managed to check it was not working again (eg password not entered), then added the IP bypass, and it now lets me in again without a password.

 

Just need to test it from a different IP address to make sure they still get the password prompt. That'll have to wait until tomorrow now.

 

Thanks for the help. Very happy with the outcome!!! :)

 

Mike

Link to comment
Share on other sites

  • Replies 107
  • Created
  • Last Reply

Top Posters In This Topic

Top Posters In This Topic

Posted Images

Ah, of course! I had wondered if I could feed it a fake password, but couldn't work out how to get the dialogue box back! Feeding it the fake details in the url is obvious when I think about it now!

 

In the meantime, I also got it working again using a different browser from the first one, which let me log-in again (or not as the case was!).

 

Managed to check it was not working again (eg password not entered), then added the IP bypass, and it now lets me in again without a password.

 

Just need to test it from a different IP address to make sure they still get the password prompt. That'll have to wait until tomorrow now.

 

Thanks for the help. Very happy with the outcome!!! :)

 

Mike

 

No Problem, Glad I could help.

 

Regards,

 

Ben

Link to comment
Share on other sites

  • 5 weeks later...
When ever I change the name of my admin dir I goto my new dir and get a blank page. ill then have to type in /login.php I can then log in but then the next page "index.php" is blank..

 

help?

 

Mate... open a new thread.

Don't completely hijack an already useful thread, it's just not cricket! ;)

Link to comment
Share on other sites

  • 2 weeks later...
Thank you for this extremely useful add-on, I will be using this shortly.

 

Glad to hear it :-)

 

When ever I change the name of my admin dir I goto my new dir and get a blank page. ill then have to type in /login.php I can then log in but then the next page "index.php" is blank..

 

help?

 

Sounds like you probably haven't set the new admin dir location in your config.php file. Read this: http://wiki.whmcs.com/Further_Security_Steps

 

Mate... open a new thread.

Don't completely hijack an already useful thread, it's just not cricket! ;)

 

It was a kind of related question, but thanks for policing the thread :P

Link to comment
Share on other sites

  • 2 weeks later...
I think it would be great to make a revision that would allow the attacker to "enter the backend", obviously a fake backend. :P

 

As cool as it would be, it doesn't really achieve anything. Looking through the log from my installed version of this, most of the requests seem to be automated anyway. It would more likely give the hacker the drive to dig deeper which isn't a favourable outcome.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated