[ic] No User Name / Password Needed for Admin Area

Christopher VanOosterhout interchange-users@lists.akopia.com
Thu Jun 7 23:31:00 2001


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


I have been using Interchange for a while and I thought I had read and 
implemented many of the security cautions issued and published in 
documentation and on the Web site.

Now I find something that concerns me a a lot.  I must have something 
mis-configured.

While it is not fully functional, I can get in to the admin area with out a 
user name or password.

I do not use this admin area at all.  In fact, I did not even know that it 
existed.  Now that I know about it, I would like to get it implemented.

As I started to explore the possibilities I found that I could pull up the 
admin area without a need for any type of authentication.

Can anyone tell me what I have done wrong.  I have searched the archive 
unsuccessfully to find an answer.  If this has already been addressed on 
the list ... (and I have missed it) can you please be so kind as to send me 
the URL for the answer in the archive.

In humility I ask for any assistance you can provide,

Chris



-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>

iQA/AwUBOyBJ+VVkc1Ov5gbPEQJSKACdFSWpHPRN1+JrFfEJvllxAsmaGM4AoPc+
nRkUbvEmi7UAzJBXsHqeAXQb
=U9g9
-----END PGP SIGNATURE-----