Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 2007-05-31 08:45:56

tameboy
Plugin Author
Registered: 2006-06-29
Posts: 48

admin interface location - changing for security

I used another CMS recently (I know, I’m sorry) and there was a strong recommendation to change the /admin/ directory. Should I be changing the /textpattern/ directory to something harder to guess for security reasons.

I’ve searched the various textpattern resources and cannot find reference to this issue.

Offline

#2 2007-05-31 10:04:46

ruud
Developer Emeritus
From: a galaxy far far away
Registered: 2006-06-04
Posts: 5,068
Website

Re: admin interface location - changing for security

Making the directory harder to find, doesn’t really make it more secure.
As far as I know there aren’t any outstanding security issues that are related to anything in the textpattern directory.

Offline

#3 2007-05-31 10:36:43

redbot
Plugin Author
Registered: 2006-02-14
Posts: 1,410

Re: admin interface location - changing for security

here and here

Offline

#4 2007-05-31 10:48:25

tameboy
Plugin Author
Registered: 2006-06-29
Posts: 48

Re: admin interface location - changing for security

Thanks ruud.

The point made in the other CMS was that it would be very easy to find the sign in pages for the admin section in an /admin/ (or in our case /textpattern/ )directory. Once a hacker finds the sign in page they could set about cracking the password.

If you were to rename it something obscure (random alpha-numeric characters), you would at least make it a lot more difficult to find in the first place.

I am no security expert, but this seems to make sense to me. I just wondered whether it was worth going to the trouble of renaming the directory? Has anybody else done this?

Offline

#5 2007-05-31 10:57:04

tameboy
Plugin Author
Registered: 2006-06-29
Posts: 48

Re: admin interface location - changing for security

redbot wrote:

here and here

I knew it would in there somewhere, thanks for that! I understand the issues now, though I don’t think I feel any surer about whether or not to do it :)

Offline

Board footer

Powered by FluxBB