osCmax v2.5 User Manual
Results 1 to 4 of 4

Security and zclass.php

This is a discussion on Security and zclass.php within the osCmax v2 Installation issues forums, part of the osCmax v2.0 Forums category; I have noticed zclass.php being installed with the cart. This is a huge security hole. Has anyone noticed this, what ...

      
  1. #1
    New Member
    Join Date
    Oct 2003
    Posts
    5
    Rep Power
    0


    Default Security and zclass.php

    I have noticed zclass.php being installed with the cart. This is a huge security hole. Has anyone noticed this, what is the purpose and can it be left out. Search it on Google and look at how many oscommerce sites have it. It is a php Shell execute program and the things you can do with it are very scary. You can delete entire sites, download and upload things. Any information about the file and it purpose in osmax would be very grateful.

  2. #2
    jpf
    jpf is offline
    osCMax Testing Team
    jpf's Avatar
    Join Date
    Sep 2003
    Location
    Manitoba, Canada
    Posts
    2,699
    Rep Power
    22


    Default RE: Security and zclass.php

    This is NOT part of OSC or MAX and is NOT included with any files. Where ever you got this information - it is wrong!

    This file (I think) is part of a program called PHP Shell by Martin Geisler (YES it can be dangerous to allow anyone "shell" access). if you installed this - or your host did as a default - then feal free to look into the program and try to remove it. Other than that I would try asking your hosting support or the program author to see if they have instruction on how to remove/restrick access to this file.

    Good Luck
    JPF - osCMax Fourm Moderator - To contact, post on the forum or click here
    Try out our osCMax at: Live Catalog Demo
    Limited access Admin: Live Admin Demo
    Feel free to add products they way you want and then purchase them -=+=- Sorry nothing will be billed or shipped!

  3. #3
    New Member
    Join Date
    Oct 2003
    Posts
    5
    Rep Power
    0


    Default Re: RE: Security and zclass.php

    Quote Originally Posted by jpf
    This is NOT part of OSC or MAX and is NOT included with any files. Where ever you got this information - it is wrong!

    This file (I think) is part of a program called PHP Shell by Martin Geisler (YES it can be dangerous to allow anyone "shell" access). if you installed this - or your host did as a default - then feal free to look into the program and try to remove it. Other than that I would try asking your hosting support or the program author to see if they have instruction on how to remove/restrick access to this file.

    Good Luck
    Sorry, you are exactly correct, it is not part of the program, and very dangerous. But here is what I have learned from the two it affected. They cannot change the includes/configure.php to 644. and therefore leaving a security hole. How do they change it. I have tried several different programs for them and continue getting the same error message on the main page; although the file appears to be 644 every where I look.

  4. #4
    jpf
    jpf is offline
    osCMax Testing Team
    jpf's Avatar
    Join Date
    Sep 2003
    Location
    Manitoba, Canada
    Posts
    2,699
    Rep Power
    22


    Default RE: Re: RE: Security and zclass.php

    What is this error your now refering to? As for zclass.php the simplest thing would to delete it.
    JPF - osCMax Fourm Moderator - To contact, post on the forum or click here
    Try out our osCMax at: Live Catalog Demo
    Limited access Admin: Live Admin Demo
    Feel free to add products they way you want and then purchase them -=+=- Sorry nothing will be billed or shipped!

Similar Threads

  1. Security..
    By ph1ngering in forum osCommerce 2.2 Installation Help
    Replies: 0
    Last Post: 03-29-2005, 08:54 AM
  2. Re: Security Patch
    By loba in forum osCmax v1.7 Discussion
    Replies: 13
    Last Post: 03-25-2005, 05:01 AM
  3. Admin Security
    By Keilup in forum osCMax v1.7 Installation
    Replies: 0
    Last Post: 10-27-2004, 06:05 AM
  4. Set Security after installation
    By cdbooks4u in forum osCMax v1.7 Installation
    Replies: 3
    Last Post: 08-24-2004, 05:41 PM
  5. Security Risk
    By AceDog in forum osCmax v1.7 Discussion
    Replies: 1
    Last Post: 03-26-2004, 02:13 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •