osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 

ANTI Cross Site Scripting attacks

This is a discussion on ANTI Cross Site Scripting attacks within the New osCommerce Contributions forums, part of the osCommerce 2.2 Forums category; I take no credit for this contribution, this is based upon the anti-xss contribution by "pixclinic" with extra sql injection ...



Find us on Facebook
Go Back   osCommerce and osCMax shopping cart software forums > osCommerce 2.2 Forums > New osCommerce Contributions

Connect with Facebook Register FAQDonate Members List Calendar Mark Forums Read


Closed Thread

 

LinkBack Thread Tools
  #1  
Old 07-19-2008, 03:13 PM
michael_s's Avatar
osCMax Developer


 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 16,740
Thanks: 150
Thanked 676 Times in 579 Posts
Rep Power: 558
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Post ANTI Cross Site Scripting attacks

I take no credit for this contribution, this is based upon the anti-xss contribution by "pixclinic" with extra sql injection protection I found elsewhere on the web.

All I have added is the extra code and logging capability.

This will basically send any hacker to log.php which will display a message that his/her IP has been logged - this is stored in a file called iplog.txt in catalog root.


3 Easy Steps.


After install head off to http://www.ncircle.com/index.php?s=p...iance#freescan to get your free pci compliance scan!

To be even safer also consider installing FWR Media's Security Pro Contribution from http://addons.oscommerce.com/info/5752




More...
__________________
Michael Sasek
osCMax Developer

*** Do not PM me requesting paid help. The only paid work I do is for AABox Web Hosting customers ***

Stay Up To Date with everything osCMax:
Free osCMax Newsletters - Security notices, New Releases, osCMax News
osCMax on Twitter - Up to the minute info as it happens. Know it first.

osCMax User Manual - osCMax Templates - Advanced Template Tutorial

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
ANTI Cross Site Scripting attacks michael_s New osCommerce Contributions 0 06-26-2008 07:20 PM
ANTI Cross Site Scripting attacks michael_s New osCommerce Contributions 0 06-26-2008 09:12 AM
ANTI Cross Site Scripting attacks michael_s New osCommerce Contributions 0 06-26-2008 03:30 AM
ScanAlert Cross site scripting XSS - Alleged Level 2 (of 5) kenlyle osCMax v2 Features Discussion 0 07-20-2006 05:59 AM


All times are GMT -8. The time now is 11:56 PM.


Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO
Copyright 2010 osCmax
Inactive Reminders By Icora Web Design