Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

Security bulletin 2008-12-18

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #41  
Old 12-22-2008, 01:15 AM
  Ene's Avatar 
Ene Ene is offline
 

X-Cart team
  
Join Date: Aug 2004
Posts: 907
 

Default Re: Security bulletin 2008-12-18

Quote:
please note since the update no users can now register again, which is what happened with the last update too...

Could you please create a new ticket in the HelpDesk regarding this matter?
We will check if this issue is related to the security patch.
__________________
Eugene Kaznacheev,
Evangelist/Product Manager at Ecwid: http://www.ecwid.com/ (since Sept 2009)

ex-Head of X-Cart Tech Support Department
ex- X-Cart Hosting Manager - X-Cart hosting
ex-X-Cart Technical Support Engineer


Note: For the official guaranteed tech support services please turn to the Customers HelpDesk.
Reply With Quote
  #42  
Old 12-22-2008, 01:16 AM
  RichieRich's Avatar 
RichieRich RichieRich is offline
 

X-Adept
  
Join Date: Sep 2004
Location: London, England
Posts: 750
 

Default Re: Security bulletin 2008-12-18

The message reads: "Please make sure all required fields are filled in" , which they are, missed orders and customers emailing about this simply dumping checkout process
__________________
Richard


Ultimate 5.4 testing
Reply With Quote
  #43  
Old 12-22-2008, 03:57 AM
  RichieRich's Avatar 
RichieRich RichieRich is offline
 

X-Adept
  
Join Date: Sep 2004
Location: London, England
Posts: 750
 

Default Re: Security bulletin 2008-12-18

SOLVED problem appears to have been username has a . in it, (ie. Username: firstname.lastname)
__________________
Richard


Ultimate 5.4 testing
Reply With Quote
  #44  
Old 12-23-2008, 08:13 AM
 
KathyHS KathyHS is offline
 

Senior Member
  
Join Date: Nov 2003
Posts: 143
 

Default Re: Security bulletin 2008-12-18

Quote:
Originally Posted by rubyaryat
Cause of remote file inclusion attack for KathyHS site was webhost had registered globals enabled in php configuration.
Also I advise all users running x-cart to enable suexec if running apache webserver.
Rubyaryat


Thanks for figuring that out, rubyaryat

(and sorry for the other)
__________________
X-Cart 4.1.11
Reply With Quote
  #45  
Old 12-27-2008, 04:38 AM
 
concepts concepts is offline
 

Senior Member
  
Join Date: Nov 2003
Posts: 104
 

Default Re: Security bulletin 2008-12-18

We applied the Dec 18th patch and still was hacked via POST commands.

We have since applied the DEC 25th patch and we'll see if they can still get through.
__________________
4.1.8
Xcart
Reply With Quote
  #46  
Old 12-29-2008, 06:59 AM
 
BritSteve BritSteve is offline
 

eXpert
  
Join Date: Apr 2006
Posts: 339
 

Default Re: Security bulletin 2008-12-18

Does anyone know whether the line of code that Jon has changed is used for both new registrations and logins? I have changed the code and added '.' as an acceptable character. I looked through our existing usernames, and both periods and @ are used by customers. I need to make sure that customers, both new and existing, are able to use these 2 characters.

Thanks for the mod Jon!

Thanks.

Steve
__________________
Version 4.1.8 & 4.1.9
ezcheckout4.1.x
cdseolinks2
product_metatags41x
shipping_per_product41x

http://www.earthsmagic.com
Reply With Quote
  #47  
Old 12-29-2008, 09:46 PM
  beetlejuice's Avatar 
beetlejuice beetlejuice is offline
 

eXpert
  
Join Date: Apr 2007
Posts: 251
 

Default Re: Security bulletin 2008-12-18

Well I'm confused that's for sure,

I manage 5 sites all but one running 4.1.9. The other runs 4.1.10.

I jumped the gun (end of year pressure) and didn't check the note re: " for use with 4.1.10 and 4.1.11" For previous versions please make sure you have installed all previous security patches" etc etc.

Went ahead and updated two 4.1.9 sites and they're perfect, the other two wouldn't allow new registrations, previous customers to log back in, nor could admin log in.
(thank god for backups )

After reading more on this forum, it seems as though the security patches quite often create more havoc than what they're meant to protect. The two sites with the problems have a prepare .php file that is so different to the new one supplied in the patch that there is no way of patching the original, I don't believe. As a test I modified all the include and payment files and then overwrote the original prepare.php with the new one from the patch, that just killed the sites stone dead.

So I've logged a ticket with QT and we'll see what they can come up with. I think gb2world's post may be be spot on, Qualteam may have had very different versions of 4.1.9 depending when they were downloaded.

I'll follow up with their response
__________________
XCart 4.5.4, 4.6.1, 4.64 stores
Many, many mods from Altered Cart
XCart Mods Reboot template
The XCart Store Templates and Mods
WCM CDSEO Pro
BCSE Rewards Points and Gallery Mods
and a few others
Reply With Quote
  #48  
Old 12-30-2008, 06:06 AM
  gb2world's Avatar 
gb2world gb2world is offline
 

X-Wizard
  
Join Date: May 2006
Location: Austin, TX
Posts: 1,970
 

Default Re: Security bulletin 2008-12-18

It will be interesting to see if QT comments on their process of having different versions of files within a distribution depending upon what date it was downloaded. Seems this has the potential hinder a smooth upgrade process.

I seem to recall that for Lite Commerce - QT developed a tool which did a comparison of the file version (the comments only) of your shop to the latest distribution so you could easily tell which files they had modified since your installation. Something like that for XCART shops would be helpful for this type of required patches.

Since QT probably does a lot of patches and responds to tickets about problems applying them - they would know if this is a concern or not. They may have a way internally of telling when a distribution is up to date with all the latest files.
__________________
X-CART (4.1.9,12/4.2.2-3/4.3.1-2/4.4.1-5)-Gold
(CDSEO, Altered-Cart On Sale, BCSE Preorder Backorder, QuickOrder, X-Payments, BCSE DPM Module)
Reply With Quote
  #49  
Old 12-30-2008, 03:47 PM
  bigredseo's Avatar 
bigredseo bigredseo is offline
 

X-Man
  
Join Date: Oct 2002
Location: Omaha, NE, USA
Posts: 2,364
 

Default Re: Security bulletin 2008-12-18

Most distributions by other companies would have an extension on the end of the version number to denote additional changes

Even putting a unix timestamp may be helpful, or just a date:
4.2.0-1230661200 = 12/30/2008 18:20
OR
4.2.0-12302008 or just 4.2.0-1230

Definitely if changes are being made to an archive, that can create serious issues (even from bug tracking point of view.
__________________
Conor Treacy - Big Red SEO - @bigredseo
Search Engine Optimization & Internet Marketing - We Bring Your Website Out Of Hiding!
If you can't be found on Google, Bing or Yahoo, you pretty much don't exist on the Internet.
Omaha SEO Office with National & Local SEO Services
Hourly Consulting - great for SEO Disaster Recovery, Audits and DIY Guidance
Reply With Quote
  #50  
Old 12-30-2008, 04:21 PM
  gb2world's Avatar 
gb2world gb2world is offline
 

X-Wizard
  
Join Date: May 2006
Location: Austin, TX
Posts: 1,970
 

Default Re: Security bulletin 2008-12-18

Since QT's development & support processes are certified under ISO 9001:2000 Quality Management System Standard - they have to be managing these distributions internally. They may not have evidence that their release process is the cause of our problems with these security patches. Right now - there is no reported solid evidence for that - unless they find this is the issue with Beetlejuice's ticket. I just know based on the problems reported in the forums - I can't apply the patches until I can resolve the differences between the current 4.1.11 distribution and an upgrade pack I used in September. I have to find time to download the current distribution and write a script to compare the version information in each file to my XCART instances.
__________________
X-CART (4.1.9,12/4.2.2-3/4.3.1-2/4.4.1-5)-Gold
(CDSEO, Altered-Cart On Sale, BCSE Preorder Backorder, QuickOrder, X-Payments, BCSE DPM Module)
Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 09:33 AM.

   

 
X-Cart forums © 2001-2020