Bug #104
closed
phpSysInfo e LightSquid - direct access without password
Added by Welkson Renny de Medeiros over 14 years ago.
Updated over 14 years ago.
Description
Hi pfSense Team!
Sorry by my poor english!
Security question:
¤https://192.168.1.1/ (login is required)
¤https://192.168.1.1/phpsysinfo/ (login NOT required)
¤https://192.168.1.1/lightsquid/index.cgi (login NOT required)
- Status changed from New to Rejected
#1 Do not assign tickts to people
#2 Use a firewall rule to prevent logins to the webGUI
Welkson Renny de Medeiros wrote:
Hi pfSense Team!
Sorry by my poor english!
Security question:
¤https://192.168.1.1/ (login is required)
¤https://192.168.1.1/phpsysinfo/ (login NOT required)
¤https://192.168.1.1/lightsquid/index.cgi (login NOT required)
#1 Sorry;
#2 webGUI accessed by various dynamics IPs;
Use a VPN then. If you need further help post to the mailing list or forum.
Scott Ullrich wrote:
Use a VPN then. If you need further help post to the mailing list or forum.
OK Scott! Thanks.
Welkson
Also available in: Atom
PDF