Sansec logo

How to grant Sansec access to your store

Sansec

by Sansec

Published in Guides

To perform an install, cleanup or forensic investigation of your system, please grant us temporary access to your (primary) production environment and log facilities.

The account you share should have read access to all of the store's files, its database and the web server access logs.

Automatic (preferred)

Log in via SSH and run:

~/bin/ecomscan remote-support

This sets up an encrypted SSH connection from your server to the Sansec office. Only Sansec staff with a hardware security key (Yubikey) can use that connection.

The connection is terminated automatically:

  • after 7 days without activity
  • when your server restarts
  • when you run ~/bin/ecomscan remote-support again

Manual

Ask your devops team or hosting partner to run these steps:

  1. Set up your firewall to allow our secure gateway IP 195.201.150.170
  2. Add our SSH public key to your webserver account (see below) and ensure correct permissions: chmod 700 ~/.ssh, chmod 600 ~/.ssh/authorized_keys
  3. Email us the server, user name and port to use for SSH at support@sansec.io.

The use of SSH is by far the most secure method to grant access. It does not require sending over passwords over insecure channels, so nothing can be intercepted. To share access, please add our SSH public key to $HOME/.ssh/authorized_keys (make sure it ends up on one line):

ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDSlrgyDEhQYmP1gihXTY/KlrDi6vUM+XlzEMlGSFglHhYRzmcB4l/LZgXDvfwXmvg+cr2wFRJJsq4G9H44qXkyVcn8h+f+rlWaMQNPlfqvdvQaFz/gJai/9hIf2WfmI5/zIF5uAzimTtz/ch9ur/23Qcic7dUeC4r6GASFFqR0Rt4zhCdOIdw2YU+5Jc2Xi7eWS3DD+Vko0j593CyMdn2iaQ1Vs2wivYvL57fd+lfNt+z2jOUOmkkOzcO4sVBZlVwVLrSYZIjHD6OcURA9j0ypwsneYAjNVBI+sjtnce/ZIncwyPSZ1oNTbImolwe1uK2zjjQSv1Gz4Z9lue1kS4LE4qba0+gnsGozbBPzAQ8v0aPr/uXDq96HCVUp8tPg/Evss3mA/AKvIKAduwVX+2Ia4h6W0jpQ103dncNF1ZdSBkbIi8NzIB+H3/nHkOfXa1jDXcudkmkXLwV1oClG4If6ZF6xet3Ao4KSgNsp6766rJPU3l9DZt86irTIMCjIRA0= sansec-gpg

Are you running Magento Cloud? In that case, please add our Magento account info@sansec.io to your project and assign admin privilege to your production environments. Afterwards, you may need to run magento-cloud environment:redeploy production in order to activate our SSH key.

Forensic investigations

If you require our forensic analysis or cleanup, please share answers to the following questions to speed up the investigation:

  1. What made you believe that your store has been compromised? Please share relevant dates and communication.
  2. Have you modified your system since the discovery? Please share recorded timestamps (creation + modification) for any files you may have (re-) moved. Please minimize code modifications until the investigation is completed, or valuable evidence may be erased.
  3. Have there been previous incidents and/or investigations?
Need expert advice? We are here to help!

Stay up to date with the latest eCommerce attacks

Sansec logo

experts in eCommerce security

Terms & Conditions
•
Privacy & Cookie Policy