Page 1 of 1
[RESOLVED] Y'all aware that the Demo Administrator button 'hacked'
Posted: Fri May 12, 2006 4:28 pm
by AtomicBob
Takes you to some inkjet refill site or somesuch. Not very useful.
Re: Y'all aware that the Demo Administrator button 'hacked'
Posted: Fri May 12, 2006 4:49 pm
by nathandiehl
thanks. this happens all the time. that's what happens when you give someone backend admin control...
(in the meantime, it looks like someone fixed it)
i'm moving this thread to official site feedback.
thanks again for the heads-up.
nathan.
Re: Y'all aware that the Demo Administrator button 'hacked'
Posted: Fri May 12, 2006 4:52 pm
by AtomicBob
Yes, i actually fixed it myself, i was suprised to find that I could figure it out - sorry for posting on a subject that must happen all the time, as you say. I should have known that. :-)
Re: Y'all aware that the Demo Administrator button 'hacked'
Posted: Fri May 12, 2006 8:29 pm
by brad
FYI The demo site refreshes every 60 mins as well.
Re: [RESOLVED] Y'all aware that the Demo Administrator button 'hacked'
Posted: Tue Jun 06, 2006 6:46 pm
by Atomm
I've been searching through the forums for a way to set up a secure Admin Demo. Almost every single post points out the site refreshes every 60 minutes and leaves it at that.
That really strikes me as a very insecure way of doing things. Can you elaborate more on how the demo site is set up and what measures have been taken to secure it. I think a lot of people would appreciate this info, myself included.
Thank you.
Atomm
Re: [RESOLVED] Y'all aware that the Demo Administrator button 'hacked'
Posted: Fri Jun 09, 2006 9:18 pm
by stingrey
Atomm wrote:I've been searching through the forums for a way to set up a secure Admin Demo. Almost every single post points out the site refreshes every 60 minutes and leaves it at that.
This refers to the fact that the Database of demo.joomla.org is emptied and repopulated with sample data from a set script
Atomm wrote:That really strikes me as a very insecure way of doing things.
Why would it be insecure the user cannot access the filesystem, database or server directly and they cannot make any modifications to files via the backend
Atomm wrote:Can you elaborate more on how the demo site is set up and what measures have been taken to secure it. I think a lot of people would appreciate this info, myself included.
http://forum.joomla.org/index.php/topic,67974.0.html