How to lock down admin directories?

This is a discussion on How to lock down admin directories? within the Cold Fusion forums in Application Servers & Tools category; I've been asked to restrict access to a site Admin directory because the site has been hacked pretty regularly. There is currently a separate web login to get to Admin, but I'm being asked if I can lock down that directory based on the NETWORK DOMAIN to endure only internal users can get to it. Is this more of an IIS issue, or is this something that can be done in CF?...

Go Back   Application Development Forum > Application Servers & Tools > Cold Fusion

Object Mix

Register FAQ Calendar Search Today's Posts Mark Forums Read
  #1  
Old 08-27-2008, 10:03 AM
loamguy
Guest
 
Default How to lock down admin directories?

I've been asked to restrict access to a site Admin directory because the site
has been hacked pretty regularly. There is currently a separate web login to
get to Admin, but I'm being asked if I can lock down that directory based on
the NETWORK DOMAIN to endure only internal users can get to it.

Is this more of an IIS issue, or is this something that can be done in CF?

Reply With Quote
  #2  
Old 08-27-2008, 10:23 AM
Ian Skinner
Guest
 
Default Re: How to lock down admin directories?

loamguy wrote:
>
> Is this more of an IIS issue, or is this something that can be done in CF?
>


Well, IIS is a great way to do stuff like this. Install the
Administrator on an IIS website and then use the Directory Security
features of that site to restrict what IP addresses that can be allowed
to view it.
Reply With Quote
  #3  
Old 08-27-2008, 11:46 AM
loamguy
Guest
 
Default Re: How to lock down admin directories?

Since it isn't the root directory, how do I do that? Set up a virtual directory on IIS?
Reply With Quote
  #4  
Old 08-27-2008, 11:50 AM
Ian Skinner
Guest
 
Default Re: How to lock down admin directories?

loamguy wrote:
> Since it isn't the root directory, how do I do that? Set up a virtual directory on IIS?


No set up second IIS website to be the home of the administrator so that
it can be removed from your public website.

Reply With Quote
Reply


Thread Tools
Display Modes


All times are GMT -5. The time now is 06:25 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
vB Ad Management by =RedTyger=

In an effort to better serve ads to our visitors, cookies are used on objectmix.com. For more information, check out our Privacy Policy.