Page 1 of 2

webmin

Posted: Thu Jul 23, 2009 3:33 pm
by weekendsrule33
when i log into webmin, i get the following:
Warning! Webmin has detected that the program http://localhost:10000/right.cgi?open=s ... pen=status was linked to from the URL http://webmin/, which appears to be outside the Webmin server. This may be an attempt to trick your server into executing a dangerous command.
If this is a legitimate link, you can allow links from this URL as follows :

Login to Webmin normally.
Go to the Webmin Configuration module.
Click on the Trusted Referrers icon.
Enter the hostname localhost into the Trusted websites field, and click Save.
Alternately, you can configure Webmin to allow this link from the command line by :

Login as root, and edit the /etc/webmin/config file.
Add the line referers=localhost at the end, or if a referers line already exists add localhost to it.
Save the file.

I cannot login to webmin because i am immediately brought to this page. I tried editing the config file, but this is still happening. Any thoughts?

Re: webmin

Posted: Thu Jul 23, 2009 5:36 pm
by cpg
when i log into webmin, i get the following:
Warning! Webmin has detected that the program http://localhost:10000/right.cgi?open=s ... pen=status was linked to from the URL http://webmin/, which appears to be outside the Webmin server. This may be an attempt to trick your server into executing a dangerous command.
hmm, well, we like short, elegant urls, not long hard to remember urls. i guess this was not tested enough.

we need a mechanism to send feedback to the packagers of the apps ...

in the mean time, perhaps someone with more expertise on webmin can help.
a bug would also help. clearly this worked for a number of people while in beta!

Re: webmin

Posted: Thu Jul 23, 2009 6:04 pm
by weekendsrule33
whats odd is that i had it working but than when i reinstalled fedora and amahi due to a hard drive failure (all my data was backed up), and reinstalled webmin, it no longer worked.

Re: webmin

Posted: Thu Jul 23, 2009 6:10 pm
by cpg
Weird. Though, webmin is a dangerous tool. Gives you enough rope to hang yourself!

Try uninstalling webmin and reinstalling?

Re: webmin

Posted: Wed Jul 29, 2009 1:38 pm
by ceayuso
Did you try restarting webmin after making the changes?

service webmin stop
service webmin start

Re: webmin

Posted: Sat Aug 08, 2009 12:32 pm
by spaceman
To access webmin from the link on the HDA page also enter "webmin.mydomain.com" in the Trusted Referers text field, as above (NOTE: replace "mydomain" with your own domain name).

To get access to this page either access webmin from a remote or console session on the HDA or try editting your address line...to http://webmin/ or http://localhost:10000/
- this may work, the link from the HDA webpage almost certainly won't.

Re: webmin

Posted: Sat Aug 08, 2009 12:42 pm
by cpg
why would the link on the hda page not work?

Re: webmin

Posted: Sat Aug 08, 2009 12:44 pm
by spaceman
It points to webmin.yourdomain.com, I had to add this to my list of Trusted Referers. I don't know why...despite announcing itself as (the working) http://webmin :mrgreen:

Re: webmin

Posted: Sat Aug 08, 2009 12:50 pm
by cpg
i see. this is like an Internet Explorer thing?

Re: webmin

Posted: Sat Aug 08, 2009 1:09 pm
by spaceman
*gag* I use Firefox! And Chrome sometimes for streaming media.