osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 
 

Is this an error, or something else?

This is a discussion on Is this an error, or something else? within the osCMax v2 Installation issues forums, part of the osCMax v2.0 Forums category; Here's what my client says is happening.. about a month ago, she said that someone placed an order from Italy ...


Go Back   osCommerce and osCMax shopping cart software forums > osCMax v2.0 Forums > osCMax v2 Installation issues

Register FAQ Members List Calendar Mark Forums Read


Free community membership! Fast easy FREE membership
Closed Thread

 

LinkBack Thread Tools
  #1  
Old 12-04-2006, 08:46 PM
Active Member
 
Join Date: May 2003
Posts: 137
Thanks: 3
Thanked 1 Time in 1 Post
Rep Power: 0
countingsheep
Default Is this an error, or something else?

Here's what my client says is happening.. about a month ago, she said that someone placed an order from Italy (she does have a registered customer in Italy), but, the ship to and billing address were from Miami, Florida. The purchase was via credit card. She attempted to process the cc, but it was declined. She then proceeded to contact the customer in Italy, but they had not placed an order. Then this evening, she said someone contacted her saying that they were placing an order without registering and when they proceeded to check out, the name, billing info, etc was already filled out in someone else's name? Is this something in the cart that I need to be looking for? If so, could anyone tell me what to be looking for?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
  #2  
Old 12-04-2006, 08:51 PM
michael_s's Avatar
osCMax Developer

 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 11,069
Thanks: 81
Thanked 348 Times in 327 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default sessions issue

The problem is that your client is hardcoding session ID's in her links, and when someone else clicks the link, they get the same session. Go through her code and find any hardcoded session ids and delete them... Then for good measure, delete all the sessions from the tmp directory...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #3  
Old 12-06-2006, 06:40 AM
Active Member
 
Join Date: May 2003
Posts: 137
Thanks: 3
Thanked 1 Time in 1 Post
Rep Power: 0
countingsheep
Default

Thank you Michael, I will do that. Appreciate your help!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #4  
Old 03-14-2007, 05:14 PM
Active Member
 
Join Date: May 2003
Posts: 137
Thanks: 3
Thanked 1 Time in 1 Post
Rep Power: 0
countingsheep
Default Re: Is this an error, or something else?

Michael, I am still having trouble with this particular site and the accounts getting mixed up. I have done a search of all files and do not see anywhere in the site that the session ids have been hard coded now. Any that were, I changed. However, she emailed me again this evening telling me that she got an email saying that someone ordered and it randomly added products to her cart, as well as ordered in someone elses name. You mentioned that I needed to delete the sessions in the tmp folder. She doesnt have a tmp folder.. I believe they are stored in the database if I am understanding everything correctly. Can you give me any more suggestions for this?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #5  
Old 03-14-2007, 06:59 PM
Active Member
 
Join Date: May 2003
Posts: 137
Thanks: 3
Thanked 1 Time in 1 Post
Rep Power: 0
countingsheep
Default Re: Is this an error, or something else?

I think I found two more places that the session ids were hardcoded. I removed those, so, hopefully this will be the last of it. If not, I may not have any hair left!!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #6  
Old 03-14-2007, 07:51 PM
michael_s's Avatar
osCMax Developer

 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 11,069
Thanks: 81
Thanked 348 Times in 327 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default Re: Is this an error, or something else?

They would not be hardcoded into any of the php files. It would be any html files external to osCMAx that you link products on or in the Define mainpage file.
__________________
Michael Sasek
osCMax Developer


  • osCMax Templates - Hundreds of premium quality templates designed for osCMax 2. Loyalty discounts up to 30% off!
    Each purchase supports the osCMax project with much needed funds!

  • xShop for osCMax - Windows Based osCMax administration. Improved workflow, security, speed and convenience.

  • osCMax Hosting - From basic hosting to High Availability, Load Balanced arrays, the most experienced osCMax host. Default multi server configuration for exceptional performance!

  • osCMax Template Tutorial - Learn how to make your own custom templates and how to use the powerful features of the osCMax template system.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #7  
Old 03-16-2007, 03:49 PM
New Member
 
Join Date: Mar 2007
Posts: 13
Thanks: 0
Thanked 3 Times in 2 Posts
Rep Power: 0
i2Paq is on a distinguished road
Default Re: Is this an error, or something else?

When you run your shop on a shared server:

Make sure you store your sessions in you database instead of in files.

Make also sure you have your cache directory renamed so it will not have the same name as another osCMax (or osCommerce) shop on this shared server.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #8  
Old 03-19-2007, 01:03 PM
Member
 
Join Date: May 2005
Posts: 35
Thanks: 1
Thanked 6 Times in 6 Posts
Rep Power: 0
argentbeads
Default Re: Is this an error, or something else?

Quote:
Originally Posted by countingsheep View Post
Here's what my client says is happening.. about a month ago, she said that someone placed an order from Italy (she does have a registered customer in Italy), but, the ship to and billing address were from Miami, Florida. The purchase was via credit card. She attempted to process the cc, but it was declined. She then proceeded to contact the customer in Italy, but they had not placed an order. Then this evening, she said someone contacted her saying that they were placing an order without registering and when they proceeded to check out, the name, billing info, etc was already filled out in someone else's name? Is this something in the cart that I need to be looking for? If so, could anyone tell me what to be looking for?
This does sound similar to scam e-mail requests our business receives all the time. Something like:

"Hello. My name is XXXXXXX XXXXXXX and I live in [Miami/Atlanta/Orlando/New York City] I am wondering if you will ship to my client in [Nairobi/Nigeria/Kenya/Burundi]. I would like to pay with a credit card.

Please get back to me soon and let me know which products you carry..."

At least two versions for the scam are:
Fraudulent Credit Card Number or
Overpay with Money Order, request for the difference to be wired immediately, then finding out that the Money Order is forged. Hopefully before the product is shipped. Otherwise, you're out the product, out the "difference" that was wired and out of time and energy to deal with it.

So it could be a scam rather than faulty programming.

Paul
OhioBeads.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -8. The time now is 03:21 PM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO
http://www.oscmax.com/forums/
Copyright 2008 osCMax