Project

General

Profile

Actions

Bug #104

closed

phpSysInfo e LightSquid - direct access without password

Added by Welkson Renny de Medeiros over 14 years ago. Updated over 14 years ago.

Status:
Rejected
Priority:
Urgent
Assignee:
Category:
-
Target version:
-
Start date:
09/28/2009
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Affected Version:
Affected Plus Version:
Affected Architecture:

Description

Hi pfSense Team!

Sorry by my poor english!

Security question:

¤https://192.168.1.1/ (login is required)

¤https://192.168.1.1/phpsysinfo/ (login NOT required)

¤https://192.168.1.1/lightsquid/index.cgi (login NOT required)

Actions #1

Updated by Scott Ullrich over 14 years ago

  • Status changed from New to Rejected

#1 Do not assign tickts to people
#2 Use a firewall rule to prevent logins to the webGUI

Actions #2

Updated by Welkson Renny de Medeiros over 14 years ago

Welkson Renny de Medeiros wrote:

Hi pfSense Team!

Sorry by my poor english!

Security question:

¤https://192.168.1.1/ (login is required)

¤https://192.168.1.1/phpsysinfo/ (login NOT required)

¤https://192.168.1.1/lightsquid/index.cgi (login NOT required)

#1 Sorry;
#2 webGUI accessed by various dynamics IPs;

Actions #3

Updated by Scott Ullrich over 14 years ago

Use a VPN then. If you need further help post to the mailing list or forum.

Actions #4

Updated by Welkson Renny de Medeiros over 14 years ago

Scott Ullrich wrote:

Use a VPN then. If you need further help post to the mailing list or forum.

OK Scott! Thanks.

Welkson

Actions

Also available in: Atom PDF