Support

Admin Tools

#23621 still secure with AdminTools, even though no https / SSL used?

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Thursday, 03 December 2015 17:20 CST

deeno
Dear team, I was wondering if you could give me a short answer about the following:

Is the website still secure against common https / SSL vulnerabilities with AdminTools, even though no https / SSL used? I am no expert in the field of security and rely fully on AdminTools. The website in mention does not have any payment details of the users stored, but the question has risen lately by a customer of this website.

If there are vulnerabilities, what would they be and how could they be resolved?

All best,
D.

dlb
They actually do two different things.

Admin Tools protects your site from various types of attacks.

The https protocol protects the communications between the user and your site by encrypting the data while it is being transmitted over the internet.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

deeno
thanks for the quick reply.
i understand that, but still have two questions:

1. if somebody manages somehow to get hold of the login data of only one registered user (only frontend) on a non-https site, is there a possibility to get hold of the data of other users as well with only the captured login data of the above mentioned user? i would say no, but again you are the experts!

2. again, same scenario as above, but this time trying to change / alter the recipient data of a shipment / package? would AdminTools be able to detect such a change, or not at all because it happens before anything gets transmitted to joomla from the browser? if so, are there any ways to prevent such changes without using https / ssl?

dlb
  1. No. The passwords are not actually stored in the site. A hash of the password is stored there. No matter what access you have, you can't see someone's password. Even you can not see the passwords. When a user types in a password, that input is hashed and the two hashes are compared. So the site does not check the password, it checks the hash of the password.

    If you had database access, you could change a user's password, make changes to the account, then change the password back. But you don't get database level access from a front end user account.
  2. Probably not. It would be up to the application software to prevent one user from changing another user's order or shipping information. Neither Admin Tools or https would have any effect within the application software.
The https protocol would protect the data "in the wire" between the user and the server. If someone intercepted the data being transmitted - a "Man in the Middle" attack - then they could potentially change the data and send the changed data on to the site. https would encrypt the data in transmission, making it impossible to read and change it.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

deeno
great, thanks for clarifying!

dlb
You are welcome!


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!