Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

Security bulletin 2008-12-18

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #31  
Old 12-21-2008, 11:44 AM
 
KathyHS KathyHS is offline
 

Senior Member
  
Join Date: Nov 2003
Posts: 143
 

Default Re: Security bulletin 2008-12-18

666 - is that okay?
__________________
X-Cart 4.1.11
Reply With Quote
  #32  
Old 12-21-2008, 11:47 AM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: Security bulletin 2008-12-18

That's writable which is probably the issue. Should have been 644. All php/tpl files should be 644 on a live site:

http://forum.x-cart.com/showthread.php?t=9163
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #33  
Old 12-21-2008, 11:48 AM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: Security bulletin 2008-12-18

And who is xxx?
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #34  
Old 12-21-2008, 11:49 AM
 
KathyHS KathyHS is offline
 

Senior Member
  
Join Date: Nov 2003
Posts: 143
 

Default Re: Security bulletin 2008-12-18

REMOVED by request of person mentioned in thread
__________________
X-Cart 4.1.11
Reply With Quote
  #35  
Old 12-21-2008, 11:50 AM
 
KathyHS KathyHS is offline
 

Senior Member
  
Join Date: Nov 2003
Posts: 143
 

Default Re: Security bulletin 2008-12-18

So I need to go through and chmod all the xcart php files to be 644....
__________________
X-Cart 4.1.11
Reply With Quote
  #36  
Old 12-21-2008, 11:51 AM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: Security bulletin 2008-12-18

Follow that link I posted - lots of things to do to make sure you are secure.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #37  
Old 12-21-2008, 12:09 PM
 
KathyHS KathyHS is offline
 

Senior Member
  
Join Date: Nov 2003
Posts: 143
 

Default Re: Security bulletin 2008-12-18

Thanks, will do. We (the system admin) created an htaccess that should be a big help to detracting hackers using remote scripts.
__________________
X-Cart 4.1.11
Reply With Quote
  #38  
Old 12-21-2008, 12:43 PM
  gb2world's Avatar 
gb2world gb2world is offline
 

X-Wizard
  
Join Date: May 2006
Location: Austin, TX
Posts: 1,970
 

Default Re: Security bulletin 2008-12-18

I think the process that QT uses for management of their files for release might explain why there are many problems with what might other wise be easy security patches. You have to be careful applying these patches if you are in this situation:

Say that you were running 4.1.10, then did an upgrade to 4.1.11 around the time of its release - example early September. You would have downloaded an upgrade pack for 4.1.10-4.1.11 from your help desk.

Unfortunately - QT continues to change what it calls 4.1.11. So, over the last few weeks - there may have been updates to many files. If you download an upgrade pack for 4.1.10-4.1.11 today - it is not the same as what you download in early September.

When you download a security patch for 4.1.11 - it is for the latest version of 4.1.11 - perhaps not the 4.1.11 version that you installed in September.

The current security patch looks like it would be okay for the XCART fresh 4.1.11 I installed earlier this month. But, the diff files have some discrepancies with a 4.1.11 cart I have that is an upgrade from a 4.1.10 cart, so I am wary to apply it without going through all the other differences - which is not an easy or quick task.
__________________
X-CART (4.1.9,12/4.2.2-3/4.3.1-2/4.4.1-5)-Gold
(CDSEO, Altered-Cart On Sale, BCSE Preorder Backorder, QuickOrder, X-Payments, BCSE DPM Module)
Reply With Quote
  #39  
Old 12-21-2008, 08:11 PM
  rubyaryat's Avatar 
rubyaryat rubyaryat is offline
 

eXpert
  
Join Date: Feb 2003
Location: Canada
Posts: 289
 

Default Re: Security bulletin 2008-12-18

Cause of remote file inclusion attack for KathyHS site was webhost had registered globals enabled in php configuration.
Also I advise all users running x-cart to enable suexec if running apache webserver.
Rubyaryat
__________________
Rubymods.com - Your X-Cart services partner for over 9 years.
Modules offered: FedEx labels, Live currency rates, GeoIP, Order Audit, Multiple e-goods.
X-Cart Store Hosting, project management and affiliates program available.
4.2.3 gold [Unix]
Reply With Quote
  #40  
Old 12-22-2008, 01:07 AM
  RichieRich's Avatar 
RichieRich RichieRich is offline
 

X-Adept
  
Join Date: Sep 2004
Location: London, England
Posts: 750
 

Default Re: Security bulletin 2008-12-18

please note since the update no users can now register again, which is what happened with the last update too...
__________________
Richard


Ultimate 5.4 testing
Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 11:07 AM.

   

 
X-Cart forums © 2001-2020