I’ve got a client that is requesting that I be able to lock down the MODx manager to only their internal IP address & ports (so the only people that can access the manager is those on the internal network or a VPN).
Is there an easy way to do this? The site is on Windows Server 2008, MySQL 5.1.51, PHP 5.3.3, Revo 2.0.2-pl.
-
MODX Staff
- 10,725 Posts
Just configure your manager directory to be located in another virtual host for Apache or another web site config if IIS that is only accessible via that IP?
OpenGeek -
I’m not sure how familiar (if at all) you are with IIS, but you’re saying you are able to add a new website that contains on the manager, and the two can work hand in hand??
-
☆ A M B ☆
- 2,475 Posts
This brings up an ongoing discussion... I should roll up my sleeves and outline a list of security measures that can help secure the manager and put it in the official docs. Here are a couple strategies that could be employed (presumably Windows has equivalents for all of these, they just charge for them):
1. Choose and enforce strong passwords, rotate them periodically
2. Rename the manager directory
3. Firewall filtering to control access to that directory (e.g. via .htaccess file)
4. Consider moving the manager to an entirely different domain and then lock down that domain using custom firewall rules.
5. Use of an .htpasswd rule can put up another layer of security
6. Filter out known bots in your .htaccess file
7. Ensure limited permissions on your web server (i.e. avoid 777 if 775 or 755 will suffice)
8. Ensure your database is accessible ONLY by the web server (no phpMyAdmin access)
9. Utilize port-knocking to activate or close ports on your server
10. https access only to your manager. How vulnerable is Revo to session-jacking?
11. SFTP access to your server only (no FTP), preferably via use of secure keys.
12. Salt the database passwords (this would be a great plugin... perhaps a good feature request too).
I’m sure there are many other strategies...
What is the security rationale for prohibiting PHPMyAdmin access?
Jason
-
☆ A M B ☆
- 24,524 Posts
PHPMyAdmin is a PHP application, and subject to attack as is any other such application. The less of a target there is for attackers, the less chance of being attacked.