osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 

Security Issues..still?

This is a discussion on Security Issues..still? within the osCMax v2 Features Discussion forums, part of the osCMax v2.0 Forums category; Hi all, Were still having problems with spamming via our OSCmax sites. I've done the security issues as far as ...


Go Back   osCommerce and osCMax shopping cart software forums > osCMax v2.0 Forums > osCMax v2 Features Discussion

Register FAQ Members List Calendar Mark Forums Read


Free community membership! Fast easy FREE membership
Closed Thread

 

LinkBack Thread Tools
  #1  
Old 06-05-2006, 08:42 AM
New Member
 
Join Date: Jul 2005
Posts: 14
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
adiwillow
Default Security Issues..still?

Hi all,

Were still having problems with spamming via our OSCmax sites. I've done the security issues as far as i'm aware, or perhaps they were done already in my version ? There is loads of '// EOF: MS2 update 501112-Added ' comments in general.php etc.. so i'm assuming they're done.

Anyway, were STILL getting blocks for email flooding on our OSC accounts..

Are there any security issues which have been overlooked? Is it possible that the Admin levels contrib is being exploited and emails are being sent from the admin panel?

i really need to sort this.. has anyone any pointers , or can anyone confirm if the 501112 security updates really are secure?

Thanks
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #2  
Old 06-11-2006, 08:26 AM
jpf's Avatar
jpf jpf is offline
Moderator

 
Join Date: Sep 2003
Posts: 1,558
Thanks: 1
Thanked 84 Times in 71 Posts
Rep Power: 10
jpf is a glorious beacon of lightjpf is a glorious beacon of lightjpf is a glorious beacon of lightjpf is a glorious beacon of lightjpf is a glorious beacon of light
Default RE: Security Issues..still?

Are you asking about "Contact us"? part. Or your just getting alot of SPAM in your inbox?

Thing to do:
- Change your email address. ONLY use a certain email box for your automated MAX mailing to your self.

- Use a differnet box for emails going out to users. IE - Automated email - do not reply - as you don't check this mailbox - type of mailbox.

- Secure your ADMIN and SQL password (change both passwords)

- Move the ADMIN to another DIR.... ie: /catalog/secret_dir/that_is/hard_to_guess/admin..... (remember to book mark it!)

- Remove the contact us screen. Or add a human confirmation code.
__________________
JPF - osCMax Fourm Moderator
Try out our osCMax at: Live Catalog Demo
Limited access Admin: Live Admin Demo
Feel free to add products they way you want and then purchase them -=+=- Sorry nothing will be billed or shipped!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #3  
Old 06-11-2006, 08:28 AM
jpf's Avatar
jpf jpf is offline
Moderator

 
Join Date: Sep 2003
Posts: 1,558
Thanks: 1
Thanked 84 Times in 71 Posts
Rep Power: 10
jpf is a glorious beacon of lightjpf is a glorious beacon of lightjpf is a glorious beacon of lightjpf is a glorious beacon of lightjpf is a glorious beacon of light
Default RE: Security Issues..still?

Are you asking about "Contact us"? part. Or your just getting alot of SPAM in your inbox?

Thing to do:
- Change your email address. ONLY use a certain email box for your automated MAX mailing to your self.

- Use a differnet box for emails going out to users. IE - Automated email - do not reply - as you don't check this mailbox - type of mailbox.

- Secure your ADMIN and SQL password (change both passwords)

- Move the ADMIN to another DIR.... ie: /catalog/secret_dir/that_is/hard_to_guess/admin..... (remember to book mark it!)

- Remove the contact us screen. Or add a human confirmation code.
__________________
JPF - osCMax Fourm Moderator
Try out our osCMax at: Live Catalog Demo
Limited access Admin: Live Admin Demo
Feel free to add products they way you want and then purchase them -=+=- Sorry nothing will be billed or shipped!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #4  
Old 07-23-2006, 11:27 AM
Member
 
Join Date: Jul 2005
Posts: 91
Thanks: 0
Thanked 1 Time in 1 Post
Rep Power: 0
kenlyle
Default RE: Security Issues..still?

I just ran a ScanAlert scan on my OSCMax domain, and they said:

"
WebApp Cross Site Scripting

The remote web application appears to be vulnerable to cross site scripting (XSS).
"
This was only two days ago...
...but they also misidentified the application as CubeCart - I am working with them...If I forget to post back within a week, somebody nudge me by PM.

Thanks,
K
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads

Thread Thread Starter Forum Replies Last Post
Other Paypal Issues timbrrr Paypal 42 04-06-2008 02:21 PM
PayPal IPN Issues usedcpus osCMax v2 Features Discussion 8 07-25-2006 04:55 AM
Help on 2 issues Please DBComics osCMax v1.7 Installation 1 04-10-2006 07:04 PM
2CO Issues auntie22 osCMax v1.7 Discussion 0 05-28-2004 11:51 AM
Are there any security issues running in root? DMG osCMax v1.7 Discussion 2 01-25-2004 05:23 AM


All times are GMT -8. The time now is 07:33 AM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO
http://www.oscmax.com/forums/
Copyright 2008 osCMax