We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 20288
    • 132 Posts
    I’ve got a client that is requesting that I be able to lock down the MODx manager to only their internal IP address & ports (so the only people that can access the manager is those on the internal network or a VPN).

    Is there an easy way to do this? The site is on Windows Server 2008, MySQL 5.1.51, PHP 5.3.3, Revo 2.0.2-pl.
      • 22303 MODX Staff
      • 10,725 Posts
      Just configure your manager directory to be located in another virtual host for Apache or another web site config if IIS that is only accessible via that IP?
        • 20288
        • 132 Posts
        OpenGeek -

        I’m not sure how familiar (if at all) you are with IIS, but you’re saying you are able to add a new website that contains on the manager, and the two can work hand in hand??
          • 22303 MODX Staff
          • 10,725 Posts
          Quote from: motoxer4533 at Dec 03, 2010, 07:51 AM

          I’m not sure how familiar (if at all) you are with IIS, but you’re saying you are able to add a new website that contains on the manager, and the two can work hand in hand??
          I haven’t tried this scenario yet on IIS, but I am familiar with IIS 7.5 and I don’t see why it wouldn’t be possible. Every physical directory and virtual URL in Revolution is configurable; it’s just a matter of properly configuring access to it via a web server configuration. For instance, we’ve developed sites where the manager was only accessible via a specific https-only subdomain. It’s all up to you.

          I’ll give this a try, when I get a chance, on my trusty Windows 7 VM to figure out the how on IIS, but the answer is yes.
            • 9207 ☆ A M B ☆
            • 2,475 Posts
            This brings up an ongoing discussion... I should roll up my sleeves and outline a list of security measures that can help secure the manager and put it in the official docs. Here are a couple strategies that could be employed (presumably Windows has equivalents for all of these, they just charge for them):

            1. Choose and enforce strong passwords, rotate them periodically
            2. Rename the manager directory
            3. Firewall filtering to control access to that directory (e.g. via .htaccess file)
            4. Consider moving the manager to an entirely different domain and then lock down that domain using custom firewall rules.
            5. Use of an .htpasswd rule can put up another layer of security
            6. Filter out known bots in your .htaccess file
            7. Ensure limited permissions on your web server (i.e. avoid 777 if 775 or 755 will suffice)
            8. Ensure your database is accessible ONLY by the web server (no phpMyAdmin access)
            9. Utilize port-knocking to activate or close ports on your server
            10. https access only to your manager. How vulnerable is Revo to session-jacking?
            11. SFTP access to your server only (no FTP), preferably via use of secure keys.
            12. Salt the database passwords (this would be a great plugin... perhaps a good feature request too).

            I’m sure there are many other strategies...
              • 37059
              • 368 Posts
              Quote from: Everett at Dec 04, 2010, 02:00 PM

              8. Ensure your database is accessible ONLY by the web server (no phpMyAdmin access)

              Huh? What about administration of custom tables? Some stuff has to be done from the backend.
                Jason
                • 9207 ☆ A M B ☆
                • 2,475 Posts
                Admin of custom tables can be done via the mysql command line on the webserver -- that’s not as user-friendly, but it’s safer. Usually security stuff is a trade-off... usually the more secure it is the more of a pain it is for the user wink so you have to evaluate what the correct balance is for any situation.
                  • 37059
                  • 368 Posts
                  What is the security rationale for prohibiting PHPMyAdmin access?
                    Jason
                    • 28042 ☆ A M B ☆
                    • 24,524 Posts
                    PHPMyAdmin is a PHP application, and subject to attack as is any other such application. The less of a target there is for attackers, the less chance of being attacked.
                      Studying MODX in the desert - http://sottwell.com
                      Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                      Join the Slack Community - http://modx.org
                      • 37059
                      • 368 Posts
                      Interesting thought. A bit too radical for me smiley but interesting.
                        Jason