osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 
 

Apparent Security Hole in Coupons/Vouchers module

This is a discussion on Apparent Security Hole in Coupons/Vouchers module within the osCMax v1.7 Discussion forums, part of the osCMax v1.7 Forums category; This is a SEVERE hole and everyone should be aware it is happening. Our store has someone that is able ...


Go Back   osCommerce and osCMax shopping cart software forums > osCMax v1.7 Forums > osCMax v1.7 Discussion

Register FAQ Members List Calendar Mark Forums Read


Free community membership! Fast easy FREE membership
Closed Thread

 

LinkBack Thread Tools
  #1  
Old 03-29-2005, 12:04 PM
HVLLC's Avatar
Lurker
 
Join Date: Mar 2005
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
HVLLC
Default Apparent Security Hole in Coupons/Vouchers module

This is a SEVERE hole and everyone should be aware it is happening.

Our store has someone that is able to give themself as many $10 vouchers as he needs to reduce the amount due to below $10. Some orders he has used $40 worth of vouchers.

This really sucks because the guy seems to know what he is doing and pays with PayPal e-check that doesn't seem to clear. If I try to refund him, it looks like Paypal will pay him out of my account regardless of whether the check clears or not!!

Anyone know how he can send himself $10 vouchers? In looking at the administration area's gift vouchers list, I see mostly where "admin" was the issuer but there are several where his user ID was the issuee.

This seems to be most often the following voucher that is getting used
---------
Discount Coupons
2005-03-29
Coupon Name Coupon 10
Coupon Name
Coupon Name
Coupon Description 10 percent off with this coupon.
Coupon Description
Coupon Description
Coupon Amount 10.0000%
Coupon Minimum Order 25.0000
Free Shipping No Free Shipping
Coupon Code 5dd5cb
Uses per Coupon 10000
Uses per Customer 1
Valid Product List
Valid Categories List
Start Date 03/29/2005
End Date 03/29/2006
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
  #2  
Old 03-29-2005, 01:07 PM
michael_s's Avatar
osCMax Developer

 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 10,505
Thanks: 74
Thanked 334 Times in 313 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default RE: Apparent Security Hole in Coupons/Vouchers module

Quote:
GV_REDEEM_EXPLOIT_FIX (GVREF)
---------------------------------------------
* case: guest accounts can exploit gift voucher sent using "Mail Gift Voucher" (admin area),
* by sharing the code until somebody logs with a valid account
* or successfully created new account.
*
* obv: the session remains on user while served as a guest.
* The gift voucher can now be reused to all guest users until
* gift voucher is redeemed
* soln: before releasing the gift voucher, the user must login first
* or asked to create an account.
*
*
-- Frederick Ricaforte
Fix is here: http://www.oscommerce.com/community/...h,gift+voucher
__________________
Michael Sasek
osCMax Developer


  • osCMax Templates - Hundreds of premium quality templates. New designs every month!

  • xShop for osCMax - Windows Based osCMax administration. Improved workflow, security, speed and convenience.

  • osCMax Hosting - From basic hosting to High Availability, Load Balanced arrays, the most experienced osCMax host.

  • osCMax Template Tutorial - Learn how to make your own custom templates and how to use the powerful features of the osCMax template system.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #3  
Old 03-31-2005, 10:32 AM
HVLLC's Avatar
Lurker
 
Join Date: Mar 2005
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
HVLLC
Default RE: Apparent Security Hole in Coupons/Vouchers module

Thanks Michael!

It seems that fix will correct the condition where he used the admin code to send himself gift vouchers. However, I am seeing where his user account has sent vouchers also.

I am afraid there is still a hole somewhere in the system allowing him to send himself vouchers for any amount and for free.

Christie
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #4  
Old 04-01-2005, 11:14 AM
Member
 
Join Date: Sep 2003
Posts: 42
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
midwestwebsites
Default Re: RE: Apparent Security Hole in Coupons/Vouchers module

Quote:
Originally Posted by msasek
Quote:
GV_REDEEM_EXPLOIT_FIX (GVREF)
---------------------------------------------
* case: guest accounts can exploit gift voucher sent using "Mail Gift Voucher" (admin area),
* by sharing the code until somebody logs with a valid account
* or successfully created new account.
*
* obv: the session remains on user while served as a guest.
* The gift voucher can now be reused to all guest users until
* gift voucher is redeemed
* soln: before releasing the gift voucher, the user must login first
* or asked to create an account.
*
*
-- Frederick Ricaforte
Fix is here: http://www.oscommerce.com/community/...h,gift+voucher
Is this fixed in OSCMAX 1.7? I don't see an upgrade patch for 1.5.5 so my first assmption would be no.

Thanks
Jonathan
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads

Thread Thread Starter Forum Replies Last Post
Tax & Coupons Just Stopped working??? toddw osCMax v2 Features Discussion 2 02-16-2006 11:16 AM
500 Internal Server Error (with no apparent reason!) Willum osCMax v2 Installation issues 5 08-19-2005 02:19 AM
Discount Coupons NickW osCMax v1.7 Discussion 1 03-26-2005 10:59 AM
Help With Credit Class / Coupons swrecruiter osCMax v1.7 General Mods Discussion 1 02-08-2004 11:50 PM
problems with coupons dreamstyles osCMax v1.7 General Mods Discussion 0 01-02-2004 03:46 PM


All times are GMT -8. The time now is 07:51 AM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO
http://www.oscmax.com/forums/
Copyright 2008 osCMax