osCmax v2.5 User Manual
Page 2 of 2 FirstFirst 12
Results 11 to 15 of 15

Strange Checkout Error Check this if you want to pay with different payment method

This is a discussion on Strange Checkout Error Check this if you want to pay with different payment method within the osCMax v2 Features Discussion forums, part of the osCmax v2.0 Forums category; Ok, you need to do some housekeeping: 1. Make sure no other vulnerable scripts are running on the account. osCmax ...

      
  1. #11
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,907
    Rep Power
    568


    Default Re: Strange Checkout Error Check this if you want to pay with different payment method

    Ok, you need to do some housekeeping:

    1. Make sure no other vulnerable scripts are running on the account. osCmax can be hacked using another script to do the dirty work.

    2. Make sure you don't have any test copies of osCmax installed anywhere on the account even if you don't use them. If they are not patched, they also can be used to hack your live cart.

    3. Search and clean the entire account for backdoors left behind. Typically a hack will also hide files so they can get back in after you have tried fixing.

    The best course of action is to back up the existing file set, then wipe it clean from the server - deleting everything. Then upload a clean new copy of your site from an un-compromised backup, that you know for a fact is clean.


    The main thing to remember here is that you missed something.
    Michael Sasek
    osCMax Developer


    osCmax Installation Service
    - Have our professionals install osCmax on your server - same day service!
    osCmax 2.5 User Manual - the must have beginners guide to osCmax v2.5

    Stay Up To Date with everything osCMax:
    Free osCmax Newsletters - Security notices, New Releases, osCMax News
    osCmax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

  2. #12
    Lurker
    Join Date
    May 2010
    Posts
    3
    Rep Power
    0


    Default Re: Strange Checkout Error Check this if you want to pay with different payment method

    greetings, i came here on your forum searching for the same problem, and i have seen that an oscommerce of a client of mine was affacted by that hack. I replaced the checkout_payment.php files whit a genuine one and i setted the permission to that file to 444 as for the config.php files. Now i have used the Threat Monitor to chek if something else is wrong and it give me a lot of alert on permissions saying to set it to 644 but if i do so any page of the websites will be displayed (can u tell me at least whic files need necessary the 444?). Another thing is the Potential Threat scanner that find some files whit double extension, is that dangerous?
    I deleted a files that was a known virus too, something like flops.php (i think that was something releated to the credit card hack)

    can u pls help me to fix those stuffs?
    thanks in advice

    Paolo

    edit: last things, can u tell me how to make the osc more secure? maybe a link to some procedure?
    forgot to say that my oscommerce is v2.2 rc2
    thanks
    Last edited by surfmaster; 05-15-2010 at 05:33 AM.

  3. #13
    osCMax Development Team
    ridexbuilder's Avatar
    Join Date
    Jul 2008
    Location
    Haggisland
    Posts
    3,014
    Rep Power
    36


    Arrow Re: Strange Checkout Error Check this if you want to pay with different payment method

    can u tell me how to make the osc more secure? maybe a link to some procedure?
    forgot to say that my oscommerce is v2.2 rc2
    You're posting this in the 'Max section! There IS an osCommerce section.
    Read the osCMax wiki on improving security.
    Hosting plans with installation, configuration, contributions, support and maintenance.

  4. #14
    osCMax Development Team
    ridexbuilder's Avatar
    Join Date
    Jul 2008
    Location
    Haggisland
    Posts
    3,014
    Rep Power
    36


    Default Re: Strange Checkout Error Check this if you want to pay with different payment method

    Threat scanner that find some files whit double extension, is that dangerous?
    Depends, though no is the simple answer.
    Do a Google search on Linux permissions, plus mod_security, plus suhosin to better understand why some (not all) should be set to 444
    Hosting plans with installation, configuration, contributions, support and maintenance.

  5. #15
    Lurker
    Join Date
    May 2010
    Posts
    3
    Rep Power
    0


    Default Re: Strange Checkout Error Check this if you want to pay with different payment method

    Quote Originally Posted by ridexbuilder View Post
    You're posting this in the 'Max section! There IS an osCommerce section.
    Read the osCMax wiki on improving security.
    ops sorry for postin in the wrong section, and thanks for your reply, btw i checked the double extension files, and are good files that i need for some smtp classes. I have renamed the admin folder and i have done some chenges at the application_top and login as sad in this topic Security issue with admin directory - osCommerce Community Support Forums ; now i need to set the permissions, i have tryed use the Check_permissions addon but i think that whit my version it isn't working, so anyone could be so kind to link me a list of the files that need to be 444 to prevent hacking, or do u wanna me to post in the other section?

    thanks for the help

Page 2 of 2 FirstFirst 12

Similar Threads

  1. No Payment Method Showing On Checkout
    By henrynowa in forum osCmax v2 Customization/Mods
    Replies: 3
    Last Post: 01-29-2010, 06:41 AM
  2. No payment method available on checkout
    By henricsson in forum osCMax v2 Features Discussion
    Replies: 12
    Last Post: 11-22-2009, 01:06 AM
  3. Added payment method : missing at checkout
    By calistared in forum osCommerce 2.2 Modification Help
    Replies: 3
    Last Post: 04-08-2008, 12:22 AM
  4. check/money order payment mod error!
    By xzyyy in forum osCmax v2 Customization/Mods
    Replies: 3
    Last Post: 10-17-2006, 07:02 PM
  5. No Payment Method Showing On Checkout
    By MysticWonder in forum osCommerce 2.2 Modification Help
    Replies: 3
    Last Post: 02-26-2003, 06:29 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •