Try the Demo

Magento Forum

   
Major Encryption Key Vulnerability
 
iPhony
Member
 
Avatar
Total Posts:  37
Joined:  2007-09-01
 

I was playing with magento and I just realized that once your store is up anyone can recover your encryption key in plain text by just adding
/install/wizard/end/
to the end of your store’s domain name.

This is critical and need to be fixed as soon as possible.
For instance you can retrieve Magento’s demo store encryption key by just launching the following link in your browser:

http://demo.magentocommerce.com/install/wizard/end/

I would like to hear from a magento team member about this is an issue.
I would rather have this key retrievable after login or simply not retrievable online but only via email or so. Not sure which one is best…

 
Magento Community Magento Community
Magento Community
Magento Community
 
Moshe
Magento Team
 
Avatar
Total Posts:  1770
Joined:  2007-08-07
Los Angeles
 

This has been fixed and will be available in next release

 Signature 

- I would love to change the world, but they won’t give me the source code -

 
Magento Community Magento Community
Magento Community
Magento Community
 
iPhony
Member
 
Avatar
Total Posts:  37
Joined:  2007-09-01
 

Great thanks for your fast reply.

 
Magento Community Magento Community
Magento Community
Magento Community
 
unknow_user
Sr. Member
 
Total Posts:  99
Joined:  2007-08-31
TX, USA
 

big surprise IPhony you’re so crafty! good job though wink

 Signature 

Web Design, SEO, Internet strategies

Le blog en Français | son Flux RSS | Le forum en Français

 
Magento Community Magento Community
Magento Community
Magento Community
 
Brandon
Sr. Member
 
Avatar
Total Posts:  76
Joined:  2007-08-31
Web Developer
 

Shouldn’t the entire install directory be deleted once installed?

 
Magento Community Magento Community
Magento Community
Magento Community
Magento Community
Magento Community
    Back to top