When perusing, "Who's online" users that are using ipinfo.php are flagged as being in an unknown location, and the syntax passed to ipinfo.php is shown.
Can normal users access this file if they observe the full URL on the whos online page?
Is it possible to change the whos online variable to, "running security checks" or something similar.
And would it be advisable to place the ipinfo.php in the admincp folder, or at least somewhere that's protected by username/password such as an .htaccess/.htpasswd protected directory on an apache server?
|