myLittleTools Community Forum

Welcome Guest Search | Active Topics | Members | Log In | Register

using sql web admin over https Options · View
BasharAnjileh
Posted: Tuesday, June 07, 2011 9:32:35 AM
Rank: Newbie
Groups: Member

Joined: 6/7/2011
Posts: 2
Points: 12
Location: syria
Dears,

I am using PLESK 9.5 and when Our company install CISCO IPS; the behavior of sql web admin in MyLittleAdmin match one of the following IPS signature

http://tools.cisco.com/go/redirect/viewSignature.x?signatureId=5474&signatureSubId=0

http://tools.cisco.com/go/redirect/viewSignature.x?signatureId=5474&signatureSubId=1

http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=5930&signatureSubId=0

http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=5930&signatureSubId=1

http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=5930&signatureSubId=2


http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=5930&signatureSubId=21

so we need to make mylittle admin to work over SSL or port other 80.

Regards
elian
Posted: Tuesday, June 07, 2011 9:55:48 AM

Rank: Administration
Groups: Administration

Joined: 9/11/2006
Posts: 605
Points: 649
Location: Enghien Les Bains, France
What is the exact question ?

The query tool sends T-SQL queries typed by the user through HTTP so that it can be executed on the server. Of course, the query can be considered like a SQL Injection attack by CISCO IPS.

You can disable access to the Query tool if needed.

BasharAnjileh
Posted: Tuesday, June 07, 2011 10:09:46 AM
Rank: Newbie
Groups: Member

Joined: 6/7/2011
Posts: 2
Points: 12
Location: syria
the question is: does the query tool can work over port other 80? and I will add exception to IPS to pass this request?
elian
Posted: Tuesday, June 07, 2011 10:21:40 AM

Rank: Administration
Groups: Administration

Joined: 9/11/2006
Posts: 605
Points: 649
Location: Enghien Les Bains, France
Yes, myLittleAdmin can work over any port.
BasharAnjileh
Posted: Tuesday, June 07, 2011 10:42:54 AM
Rank: Newbie
Groups: Member

Joined: 6/7/2011
Posts: 2
Points: 12
Location: syria
And what about Silent login from Plesk ?!!
elian
Posted: Tuesday, June 07, 2011 4:03:57 PM

Rank: Administration
Groups: Administration

Joined: 9/11/2006
Posts: 605
Points: 649
Location: Enghien Les Bains, France
Silent login from Plesk is sending connection values through http requests.
Check with Parallels how to modify the silent login url (should be available in one of their config files)
burt84paxton
Posted: Friday, June 17, 2011 2:06:12 PM

Rank: Newbie
Groups: Member

Joined: 6/17/2011
Posts: 2
Points: -91
Location: 2495 S Industrial Park Ave,Tempe, AZ 85282-1804
Can you give the steps how to check ?
elian
Posted: Tuesday, June 21, 2011 8:33:28 AM

Rank: Administration
Groups: Administration

Joined: 9/11/2006
Posts: 605
Points: 649
Location: Enghien Les Bains, France
You can silently log into myLittleAdmin by posting connection info to the silentlogon.aspx page. It is explained in the following doc :
http://livedemo.mylittleadmin.com/livedemo/silent%20logon.pdf

Plesk is using this method.
Users browsing this topic
Guest


You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.

Main Forum RSS : RSS

Theme created by myLittleTools
Powered by Yet Another Forum.net version 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.