Nikola Pavlović, Marko Šarac, S. Adamovic, Miloš Mravik
{"title":"Magento CMS安全的魅力","authors":"Nikola Pavlović, Marko Šarac, S. Adamovic, Miloš Mravik","doi":"10.15308/Sinteza-2019-223-228","DOIUrl":null,"url":null,"abstract":"Magento is a CMS (Content Management System) platform used to create e-commerce websites and online stores. With it, users can fully manage their online store, display specific products, provide customers with different methods of payment and delivery, as well as many other options. Magento uses an authentication system based on the knowledge of the user name and password. In addition to increasing this problem, there is no mechanism that prevents an attacker from brute forcing passwords. The proposed solution is replacing default Magento authentication with OAuth.","PeriodicalId":342313,"journal":{"name":"Proceedings of the International Scientific Conference - Sinteza 2019","volume":"98 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Enchantment of Magento CMS Security\",\"authors\":\"Nikola Pavlović, Marko Šarac, S. Adamovic, Miloš Mravik\",\"doi\":\"10.15308/Sinteza-2019-223-228\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Magento is a CMS (Content Management System) platform used to create e-commerce websites and online stores. With it, users can fully manage their online store, display specific products, provide customers with different methods of payment and delivery, as well as many other options. Magento uses an authentication system based on the knowledge of the user name and password. In addition to increasing this problem, there is no mechanism that prevents an attacker from brute forcing passwords. The proposed solution is replacing default Magento authentication with OAuth.\",\"PeriodicalId\":342313,\"journal\":{\"name\":\"Proceedings of the International Scientific Conference - Sinteza 2019\",\"volume\":\"98 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"1900-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the International Scientific Conference - Sinteza 2019\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.15308/Sinteza-2019-223-228\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the International Scientific Conference - Sinteza 2019","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.15308/Sinteza-2019-223-228","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Magento is a CMS (Content Management System) platform used to create e-commerce websites and online stores. With it, users can fully manage their online store, display specific products, provide customers with different methods of payment and delivery, as well as many other options. Magento uses an authentication system based on the knowledge of the user name and password. In addition to increasing this problem, there is no mechanism that prevents an attacker from brute forcing passwords. The proposed solution is replacing default Magento authentication with OAuth.