Alex Rivera | Logout

What are best practices for securing the admin section of a website?

Asked 2010-05-17T10:06:25.763
101

I'd like to know what people consider best practice for securing the Admin sections of websites, specifically from an authentication/access point of view.

Of course there are obvious things, such as using SSL and logging all access, but I'm wondering just where above these basic steps people consider the bar to be set.

For example:

  • Are you just relying on the same authentication mechanism that you use for normal users? If not, what?
  • Are you running the Admin section in the same 'application domain'?
  • What steps do you take to make the admin section undiscovered? (or do you reject the whole 'obscurity' thing)

So far, suggestions from answerers include:

  • Introduce an artificial server-side pause into each admin password check to prevent brute force attacks [Developer Art]
  • Use separate login pages for users and admin using the same DB table (to stop XSRF and session-stealing granting access to admin areas) [Thief Master]
  • Consider also adding webserver native authentication to the admin area (e.g. via .htaccess) [Thief Master]
  • Consider blocking users IP after a number of failed admin login attempts [Thief Master]
  • Add captcha after failed admin login attempts [Thief Master]
  • Provide equally strong mechanisms (using the above techniques) for users as well as admins (e.g. don't treat admins specially) [Lo'oris]
  • Consider Second level authentication (e.g. client certificates, smart cards, cardspace, etc.) [JoeGeeky]
  • Only allow access from trusted IPs/Domains, add check to basic HTTP pipeline (via e.g. HttpModules) if possible. [JoeGeeky]
  • [ASP.NET] Lock down IPrincipal & Principal (make them immutable and non-enumerable) [JoeGeeky]
  • Federate Rights Elevation - e.g. email other admins when any admin's rights are up
Edit
Report

3 Answers

9
  • I reject obscurity
  • Using two authentication systems instead of one is overkill
  • The artificial pause between attempts should be done for users too
  • Blocking IPs of failed attempts should be done for users too
  • Strong passwords should be used by users too
  • If you consider captchas ok, guess what, you could use them for users too

Yes, after writing it, I realize that this answer could be summarized as a "nothing special for the admin login, they are all security features that should be used for any login".

answered 2010-05-17T11:15:55.643
1

Here are some other things to consider:

  1. One option to consider, especially if you manage the admin's computers or they are technically competent, is to use something based on SSL certificates for client authentication. RSA keyfobs and whatnot can also be used for added security.
  2. If you're using cookies at all - perhaps for an authentication/session token - you probably want to ensure that the cookies are only sent to the admin pages. This helps mitigate the risks posed to your site by stealing cookies, by either layer 1/2 compromise or XSS. This can be done easily by having the admin portion being on a different hostname or domain as well as setting the secure flag with the cookie.
  3. Restricting by IP can be smart as well, and if you have users throughout the internet you can still do this, if there is a trusted VPN that they can join.
answered 2010-05-25T18:10:52.727
-4

Add a password field and a security question that the Administrator will know, e.g. what was your first girlfriend name, or randomize the questions everytime viewing the admin panel.

Perhaps you could always put the administration section in a big directory, e.g.

http://domain.com/sub/sub/sub/sub/sub/index.php

But that's not really good hah.

Perhaps you could include a query string in the home page, like:

http://domain.com/index.php?display=true

When it does, the username and password field will appear.

answered 2010-06-01T12:39:00.310

Your Answer