How to grant Sansec access to your store
by Sansec
Published in Guides
To perform an install, cleanup or forensic investigation of your system, please grant us temporary access to your (primary) production environment and log facilities.
The account you share should have read access to all of the store's files, its database and the web server access logs.
Automatic (preferred)
Log in via SSH and run:
~/bin/ecomscan remote-support
This sets up an encrypted SSH connection from your server to the Sansec office. Only Sansec staff with a hardware security key (Yubikey) can use that connection.
The connection is terminated automatically:
- after 7 days without activity
- when your server restarts
- when you run
~/bin/ecomscan remote-supportagain
Manual
Ask your devops team or hosting partner to run these steps:
- Set up your firewall to allow our secure gateway IP
195.201.150.170 - Add our SSH public key to your webserver account (see below) and ensure correct permissions:
chmod 700 ~/.ssh,chmod 600 ~/.ssh/authorized_keys - Email us the server, user name and port to use for SSH at support@sansec.io.
The use of SSH is by far the most secure method to grant access. It does not require sending over passwords over insecure channels, so nothing can be intercepted. To share access, please add our SSH public key to $HOME/.ssh/authorized_keys (make sure it ends up on one line):
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDSlrgyDEhQYmP1gihXTY/KlrDi6vUM+XlzEMlGSFglHhYRzmcB4l/LZgXDvfwXmvg+cr2wFRJJsq4G9H44qXkyVcn8h+f+rlWaMQNPlfqvdvQaFz/gJai/9hIf2WfmI5/zIF5uAzimTtz/ch9ur/23Qcic7dUeC4r6GASFFqR0Rt4zhCdOIdw2YU+5Jc2Xi7eWS3DD+Vko0j593CyMdn2iaQ1Vs2wivYvL57fd+lfNt+z2jOUOmkkOzcO4sVBZlVwVLrSYZIjHD6OcURA9j0ypwsneYAjNVBI+sjtnce/ZIncwyPSZ1oNTbImolwe1uK2zjjQSv1Gz4Z9lue1kS4LE4qba0+gnsGozbBPzAQ8v0aPr/uXDq96HCVUp8tPg/Evss3mA/AKvIKAduwVX+2Ia4h6W0jpQ103dncNF1ZdSBkbIi8NzIB+H3/nHkOfXa1jDXcudkmkXLwV1oClG4If6ZF6xet3Ao4KSgNsp6766rJPU3l9DZt86irTIMCjIRA0= sansec-gpg
Are you running Magento Cloud? In that case, please add our Magento account info@sansec.io to your project and assign admin privilege to your production environments. Afterwards, you may need to run magento-cloud environment:redeploy production in order to activate our SSH key.
Forensic investigations
If you require our forensic analysis or cleanup, please share answers to the following questions to speed up the investigation:
- What made you believe that your store has been compromised? Please share relevant dates and communication.
- Have you modified your system since the discovery? Please share recorded timestamps (creation + modification) for any files you may have (re-) moved. Please minimize code modifications until the investigation is completed, or valuable evidence may be erased.
- Have there been previous incidents and/or investigations?
In this article
Protect your store now!
Block all known Magento attacks, while you schedule the latest critical patch until a convenient moment. No more downtime and instability from rushed patching.
Get Sansec Shield