Jump to content

Making sure the 4.0 upgrade is secure


jeds

Recommended Posts

Hi,

 

After upgrading to 4.0, I have reviewed the steps for securing a new installation, bringing forth some questions:

 

From "securing your new installation" (or similar title):

1. Rename the file configuration.php.new to configuration.php

 

The upgraded installation has a blank configuration.php.new, while configuration.php has the entries from old installation per below.

 

Should configuration.php.new be deleted?

 

 

2. chmod /configuration.php /attachments /downloads /templates_c to 777

(unless your php is suPHP or PHPSuExec) and move three folders "attachments", "downloads" and "templates_c" outside Public accesible folder tree

 

The new install has placed new copies back inside the whmcs, but the old ones still exist in the location I moved them to and have been chmod'd. As well, the new config file contains the paths as originally edited

 

Do I delete the new ones?

 

Finally, Also at my host's forum it has been mentioned to password protect the admin folder from the control panel. It is password protected by default, is this necessary?

Link to comment
Share on other sites

merlinpa1969,

 

If I would use .htaccess to deny all and allow only IPs of admins/staff allowed in the admin, then why would even bother renaming admin folder if only allowed IPs would be allowed in the admin? I understand that it is an extra step toward insuring security, (and personally I wouldn't mind mind to take all possible steps) but I would appreciate any thoughts about my question above.

 

Sincerely,

Serg

Edited by HostBizLng
Link to comment
Share on other sites

any level of security you can add is never a bad thing,

Yes renaming the admin looks like overkill but we actually have a dummy admin that tracks and emails us anytime someone tries to access it

 

Does the dummy admin page look like a normal WHMCS admin login? I'm interested to see how you have that set up. :)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated