| ||||||||||
![]() |
Shopping cart software Solutions for online shops and malls | |||||||||
![]() |
![]() |
|
X-Cart Home | ![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
[PATCH] Blocking those pesky hackers | ||||
![]() |
|
|
Thread Tools | Search this Thread |
#41
|
|||||||
|
|||||||
![]() I figured there had to be a way to make the part before the HTTP a wildcard of some kind.
![]() One more reason to learn more about PHP. I dabble enough to be dangerous and can reverse-engineer it with the best of them.... just don't fully get the syntax sometimes.
__________________
Xcart Version 4.1.9 Upgraded to 4.1.10 (clean install with mods added back) |
|||||||
#42
|
|||||||
|
|||||||
![]() |
|||||||
#43
|
|||||||
|
|||||||
![]() Heh.... I'm not THAT good... LOL
![]()
__________________
Xcart Version 4.1.9 Upgraded to 4.1.10 (clean install with mods added back) |
|||||||
#44
|
|||||||||
|
|||||||||
![]() Here are the two patches plus the sql file for 4.0.x
I tested them on my 4.0.19 and they're working fine.
__________________
Jack@AquasanaCA X-CART GOLD 4.0.19 Live DSEFU, AOM, ezCheckout, ezUpsell, ezRecommends, RememberMe, RememberAnonCarts AquasanaCanada.com - Aquasana╝ - #1 Rated Water Filters in America! X-CART GOLD 4.4.5 Live CDSEO Pro v. 1.8.4 AquasanaMontreal.com Aquasana╝ & Rhino Water Filtration Systems |
|||||||||
#45
|
|||||||
|
|||||||
![]() @imexhouse: thanks for your contribution!
Hi Scott, this should work: PHP Code:
|
|||||||
#46
|
|||||||
|
|||||||
![]() Quote:
Where does this code go, in the auth.php file? Thanks, Mike
__________________
X-Cart 4.3.1 Buy Together Module, AlteredCart CDSEO Pro One Page Checkout, AlteredCart Smart Search, AlteredCart On Sale, AlteredCart |
|||||||
#47
|
|||||||
|
|||||||
![]() Hi Mike, yes, it replaces *some* of the code that you would have already added, using the patch file.
So nothing gets confused in copy/paste, here's an updated patch file. EDIT: if you want to use the patch file via X-Cart admin, you'll need to reverse the previous patch (by uploading it to Patch/Upgrade and selecting "yes" for Reverse). Then you'll need to apply this patch. Cheers |
|||||||
#48
|
|||||||
|
|||||||
![]() I started getting these URLs in the Users Online log. Is there a way I can block these too?
HTML Code:
__________________
Xcart Version 4.1.9 Upgraded to 4.1.10 (clean install with mods added back) |
|||||||
#49
|
|||||||||
|
|||||||||
![]() I've been getting the same code in my logs (;DECLARE%20@S%20CHAR(4000); ....). I did some research: http://isc.sans.org/diary.html?storyid=4844
__________________
__________________ XC5: 5.3.4.4 PHP: 7.0.26 MySQL server: 5.5.56-MariaDB |
|||||||||
#50
|
|||||||
|
|||||||
![]() Noticing a lot of these too... anyone got a good solution to block these? They appear to be coming from many different IP addresses, so individual IP blocks would be impratical.
Even if they arent getting in, it would be good to have a way to deflect them before they do figure out a way in. /?';DeCLARE%20@S%20CHAR(4000);SET%20@S=CAST%20AS%20 CHAR(4000));ExEC(@S);............................. ........................... (theres about 1200 characters total according a text editor that I pasted it into that does character count. )
__________________
X-Cart Gold 4.6.3 Codero dedicated server |
|||||||
|
|||
X-Cart forums © 2001-2020
|