Toon posts:

[phpmyadmin].htaccess beveiligd maar...

Pagina: 1
Acties:
  • 50 views sinds 30-01-2008

Verwijderd

Topicstarter
Als ik nu van buiten mijn phpmyadmin wil bereiken dan krijg ik paginas die niet bereikbaar zijn.
Is dit normaal ?

  • Bosmonster
  • Registratie: Juni 2001
  • Laatst online: 19-08 22:14

Bosmonster

*zucht*

Van buiten? Als je met je laptop in de tuin zit bedoel je? Of iets anders?

En hoe zit je htaccess bestand eruit..

More info!

  • jan-marten
  • Registratie: September 2000
  • Laatst online: 23:02
AuthUserFile .administrators
AuthGroupFile /dev/null
AuthName 'Administrators only'
AuthType Basic
require valid-user
ALLOW from ALL

zo moet ie er toch uitzien?

Verwijderd

Topicstarter
AuthGroupFile /dev/null
ALLOW from ALL
deze heb ik er niet in staan.
Server draait wel onder W2K.

[ Voor 18% gewijzigd door Verwijderd op 17-01-2003 14:25 ]


Verwijderd

zet die er eens bij dan :)
volgens mij is AuthGroupFile optioneel, but i'm not sure

Verwijderd

zo ziet mijn .htaccess eruit, dus ik denk ook dat je AuthGroupFile /dev/null erbij moet zetten
code:
1
2
3
4
5
6
7
8
9
10
AuthUserFile /.htpasswd
AuthName "Admin selection"
AuthType Basic


AuthGroupFile /dev/null

<Limit GET POST>
require valid-user
</Limit>

Verwijderd

Topicstarter
Maar kan het ook niet zijn dat ik .htaccess en .htpasswd in de map phpmyadmin heb staan, of is dat geen probleem ??

Verwijderd

Verwijderd schreef op 17 januari 2003 @ 15:28:
Maar kan het ook niet zijn dat ik .htaccess en .htpasswd in de map phpmyadmin heb staan, of is dat geen probleem ??
Het is veiliger om .htpasswd buiten je webroot te hebben staan ;)
Ik heb ze gewoon in c:\ gezet...werkt perfect.

  • reskobon
  • Registratie: November 2001
  • Laatst online: 14-08 22:26
Dit is mijn htaccess

code:
1
2
3
4
AuthType Basic
AuthName "Hey vul even je password in!"
AuthUserFile /usr/local/apache/passwords/.htpasswd
Require user rob


Dit zijn de minimale eisen die je nodig hebt en vergeet het ook neit even aan te zetten in httpd.conf!!

Leeg


  • Postman
  • Registratie: Februari 2000
  • Laatst online: 15-08 20:11
code:
1
2
3
4
5
6
7
8
AuthUserFile /home/sites/web/dir/.htpasswd
AuthName "Password required!"
AuthType Basic
AuthPAM_Enabled off

<limit GET>
require valid-user
</limit>

En maak je password aan met het (ht)passwd tooltje dat bij Apache zit, zo weet je zeker dat je w8woord klopt.

Verwijderd

zijn je pages zonder .htaccess wel bereikbaar dan :? ....
beetje vaag

  • StephanL
  • Registratie: Juni 2001
  • Laatst online: 17-07 08:14
Je kan ook phpmyadmin beveiligen zonder htacces door de volgende regel aan te passen naat http,

code:
1
2
$cfg['Servers'][$i]['auth_type']     = 'http';   
 // Authentication method (config, http or cookie based)?


dan krijg je een pop-up scherm waar je je username en paswoord moet invullen. Lezen van de manual is nooit de sterkste kant van tweakers.

[ Voor 14% gewijzigd door StephanL op 17-01-2003 20:18 ]


  • Postman
  • Registratie: Februari 2000
  • Laatst online: 15-08 20:11
StephanL schreef op 17 januari 2003 @ 20:17:
Lezen van de manual is nooit de sterkste kant van tweakers.
Of juist wel. Zij adviseren immers om htaccess te gebruiken. HTTP komt als 2de, en dan pas cookies.

Verwijderd

FlamerX schreef op 17 januari 2003 @ 20:22:
[...]

Of juist wel. Zij adviseren immers om htaccess te gebruiken. HTTP komt als 2de, en dan pas cookies.
Uhm ... nee.
Using authentication modes:

Http and cookie authentication modes are recommended in a multi-user environment where you want to give users access to their own database and don't want them to play around with others.
Nevertheless be aware that MS Internet Explorer seems to be really buggy about cookies, at least till version 6. And php 4.1.1 is also a bit buggy in this area!
Even in a single-user environment, you might prefer to use http or cookie mode so that your user/password pair are not in clear in the configuration file.


Http and cookie authentication modes are more secure: the MySQL password does not need to be set in the phpMyAdmin configuration file (except for the "controluser" -see the Configuration section-).
However, keep in mind that the password travels in plain text, unless you are using the https protocol.
In cookie mode, we send the password in a temporary cookie, so most browsers should not store the password in their cookie file.
Kortom, gebruik auth. mode 'http', en je krijgt vrijwel hetzelfde effect als het aanpassen van .htaccess, mogelijk gemaakt door de makers van phpMyAdmin

  • Bigs
  • Registratie: Mei 2000
  • Niet online
Verwijderd schreef op 17 januari 2003 @ 14:26:
zet die er eens bij dan :)
volgens mij is AuthGroupFile optioneel, but i'm not sure
/dev/null onder windows? Ik denk niet dat dat echt helpt.. tis overigens een optionele optie (uhh :) ).

Verwijderd

Verwijderd schreef op 17 januari 2003 @ 19:47:
zijn je pages zonder .htaccess wel bereikbaar dan :? ....
beetje vaag
Ja :)
-Geen .htaccess in een map -> iedereen kan die map + submappen bekijken.
-Wel .htaccess in een map -> die map + submappen kunnen alleen na inloggen worden bekeken.

Verwijderd

Topicstarter
Iedereen bedankt, het is gelukt !!!

  • martinvw
  • Registratie: Februari 2002
  • Laatst online: 14-12-2025
Verwijderd schreef op 17 januari 2003 @ 20:44:
[...]

Ja :)
-Geen .htaccess in een map -> iedereen kan die map + submappen bekijken.
-Wel .htaccess in een map -> die map + submappen kunnen alleen na inloggen worden bekeken.
Dit was duidelijk een vraag aan de topic starter en geen vraag over hoe .htaccess werkt ;)

  • drm
  • Registratie: Februari 2001
  • Laatst online: 09-06-2025

drm

f0pc0dert

Online:
Iedereen bedankt, het is gelukt !!!

Goed zo... Volgende keer beetje beter door de software heenkijken die je gebruikt, en de manual van Apache is ook niet mis.

Music is the pleasure the human mind experiences from counting without being aware that it is counting
~ Gottfried Leibniz

Pagina: 1

Dit topic is gesloten.