lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <440CCE35.1000301@csc.liv.ac.uk> Date: Tue Mar 7 00:05:44 2006 From: cs3jm at csc.liv.ac.uk (Jodi Middleton) Subject: Simple Oscommerce Google inurl trick Simply google inurl trick for Oscommerce for open administrator page. If no .htpassword is set for the admin folder of osCommerce then of course you can change any setting in the shop unless password security has been enabled on the admin console. Search google for; inurl:"/admin/configuration. php?" Mystore Despite a few demo pages there are a few open admin pages for webshops. Simple patch if you are one is to place a .htpassword file in the root of the admin folder. -- J.R.Middleton