View Single Post
  #3  
Old 11-14-2013, 06:31 AM
 
carpeperdiem carpeperdiem is offline
 

X-Guru
  
Join Date: Jul 2006
Location: New York City, USA
Posts: 5,399
 

Default Re: security-patch-2013-10-08

Quote:
I have checked your HelpDesk profile and noticed that "Security updates and alerts:" checkbox in "Newsletter" section is not selected.

Obviously, not something I would do. And if I were X-Cart, I wouldn't offer unsubscribing from security and alert emails as an option. Security alerts must be sent, even if the user doesn't want to receive them. PS -- I never unsubscribed from any xcart emails. If you are an x-cart cusotmer and reading this, I suggest you check your communications prefs in your account profile in case you were switched off too.

Quote:
Some users have even discussed the patch on our forum (http://forum.x-cart.com/showthread.php?t=68019, http://forum.x-cart.com/showthread.php?t=67911).
But the title of the thread is "SQL error notification injection attack?" - unless you expect everyone to read every post (impossible for non-X-Cart staff, right?) -- and there was no post in the News and Announcements sub-forum (where it should have been posted at same time as email).

Quote:
Another way I used to inform the customers is a 'news' in HelpDesk. It was shown on October,ctober 21st. Probably you haven't visited HelpDesk during that period, or haven't paid attention to the announcement.

I only visit the helpdesk home page, well, never -- I have deep links to the file area and communications center.

THE ONLY WAY to reach everyone is mandatory email for these types of alerts (and a post in the news section of the forum here).

I appreciate your response here -- and I look forward to discussing the technical aspects of this patch with engineering. Thanks!
Jeremy
__________________
xcart 4.5.4 gold+ w/x-payments 1.0.6; xcart gold 4.4.4
Reply With Quote