Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

security-patch-2007-10-29.tgz

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #61  
Old 11-10-2007, 11:36 AM
 
digiemp digiemp is offline
 

Senior Member
  
Join Date: Aug 2007
Posts: 192
 

Default Re: security-patch-2007-10-29.tgz

So if I added everything for my version, since the email told me to add everything, is it going to slow my site down? I now see that some things like magnifyer and RMA were not needed if I didn't already have them installed. I probably should have came here first but I decided to back up everything and then replace everything (even if it didn't exist previously) like the good robot I am.

I don't have a lot of mods but everything seems to be working fine. Or at least as good as it was.

Thanks,
__________________
version 4.4.2
Reply With Quote
  #62  
Old 11-10-2007, 11:47 AM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: security-patch-2007-10-29.tgz

I would suggest to anyone reading this post that you DO NOT attempt to patch your carts using the current patch/files. Wait until next week when X-Cart (hopefully) releases a revised set of patch files.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #63  
Old 11-10-2007, 11:48 AM
 
donmck donmck is offline
 

Senior Member
  
Join Date: Dec 2005
Location: Australia
Posts: 137
 

Default Re: security-patch-2007-10-29.tgz

Quote:
Originally Posted by digiemp
So if I added everything for my version, since the email told me to add everything, is it going to slow my site down? I now see that some things like magnifyer and RMA were not needed if I didn't already have them installed. I probably should have came here first but I decided to back up everything and then replace everything (even if it didn't exist previously) like the good robot I am.

I don't have a lot of mods but everything seems to be working fine. Or at least as good as it was.

Thanks,

No, extra files for mods that you don't have, won't slow your site.

Considering your level of knowledge, I think I would be waiting for the new diff files.

X-cart said they will come up with a working set this week.
I just found an interesting free diffmerge program, that operates using 3 file windows. I may play with that until the new diff files appear.

Trouble is, any new program always takes a couple of hours to get into it.

Cheers Don...
__________________
Don McKenzie

http://www.dontronics-shop.com/
X-Cart 4.0.17 [Unix]

█ Hosting by www.totalserversolutions.com The very best home for your X-Cart. (was ewdhosting.com)
Reply With Quote
  #64  
Old 11-10-2007, 11:52 AM
 
geckoday geckoday is offline
 

X-Wizard
  
Join Date: Aug 2005
Posts: 1,073
 

Default Re: security-patch-2007-10-29.tgz

Quote:
Originally Posted by digiemp
So if I added everything for my version, since the email told me to add everything, is it going to slow my site down? I now see that some things like magnifyer and RMA were not needed if I didn't already have them installed. I probably should have came here first but I decided to back up everything and then replace everything (even if it didn't exist previously) like the good robot I am.

I don't have a lot of mods but everything seems to be working fine. Or at least as good as it was.

Thanks,
It won't hurt to add the extra files for addon modules you don't have and it won't slow anything down. X-Cart checks to see if the modules are turned on in the admin first before including the module files so they will just sit there and never be used.

And for those contemplating the upgrade to 4.1.9 instead of applying the patch: you should read the thread on upgrading to 4.1.9 before deciding to try it. It doesn't sound pretty - definitely not something I would jump into this close to the holiday selling season.
__________________
Manuka Bay Company
X-Cart Version 4.0.19 [Linux]

UGG Boots and other fine sheepskin products
http://www.snowriver.com
Reply With Quote
  #65  
Old 11-10-2007, 10:58 PM
 
donmck donmck is offline
 

Senior Member
  
Join Date: Dec 2005
Location: Australia
Posts: 137
 

Default Re: security-patch-2007-10-29.tgz

Quote:
Originally Posted by donmck
I just found an interesting free diffmerge program, that operates using 3 file windows. I may play with that until the new diff files appear.

Trouble is, any new program always takes a couple of hours to get into it.

Well as it turned out it didn't.
Program is SourceGear DiffMerge.
Firstly, I backed up func.php

I placed the new file in the left window, my current file in the right window, and with 3 navigation arrows, went through the file doing the changes, patch by patch. In fact, I did it about 6 times just for the practice to make sure it appeared OK, and that I was satisfied.

It didn't take an hour, including the 6 dry runs and the learning curve.

I uploaded the newly created file, tested it as best I could, no errors, so if you don't hear back from me on this one, I got it right.

My cart is heavily modded, and most of it was done by x-cart.

Cheers Don...
__________________
Don McKenzie

http://www.dontronics-shop.com/
X-Cart 4.0.17 [Unix]

█ Hosting by www.totalserversolutions.com The very best home for your X-Cart. (was ewdhosting.com)
Reply With Quote
  #66  
Old 11-11-2007, 10:58 PM
 
ironmansp ironmansp is offline
 

Member
  
Join Date: Nov 2007
Posts: 24
 

Default Re: security-patch-2007-10-29.tgz

This was he main reason I suggest an extra mod manager. With this extra mod manager, you should be able to unistall your modifications and leave the soft as fresh install version, apply the security or upgrade patch and reinstall the extra managers in order to see if the extra mod changes something important and they are compatible with the new version or not. Actually,with these "changes" we should patch every shop manually wasting several hours. If the extra mod does not work ok with the new release we decide to use the old version with the mod or the new wih the patch, but it is our decision.

This is my opinion as developer,sorry to be a little hard, but I hope that our shops are the first. I expect that Qualiteam gets ideas for this situation in order to not to repeat,and implement a method with quality tests.
__________________
Xcart in Spain
4.1.9
Reply With Quote
  #67  
Old 11-11-2007, 11:07 PM
  ambal's Avatar 
ambal ambal is offline
 

X-Cart team
  
Join Date: Sep 2002
Posts: 4,125
 

Exclamation Re: security-patch-2007-10-29.tgz

Hello Everyone,

Quote:
Originally Posted by balinor
I would suggest to anyone reading this post that you DO NOT attempt to patch your carts using the current patch/files. Wait until next week when X-Cart (hopefully) releases a revised set of patch files.

First of all I must admit that we were in hurry with making the .DIFF files and it was the reason of the situation we can see now.

I am sorry for the situation and troubles it caused.

We are going to publish the improved patch with corrected .DIFF files and some explanations within next few days. I understand that this is not really fast, but we have already been in hurry with this once and now all of us (Qt and the community) can see the results. Since so many X-Cart versions are affected we need to be careful. At the moment the improved version of the patch is being tested by our Software QA dept. Once they approve it we'll make an announcement here and in your HelpDesk accounts.

Thank you for your patience.
__________________
Sincerely yours,
Alex Mulin
VP of Business Development for X-Cart
X-Payments product manager
Reply With Quote
  #68  
Old 11-13-2007, 06:40 AM
 
kevinperson kevinperson is offline
 

eXpert
  
Join Date: May 2007
Posts: 201
 

Default Re: security-patch-2007-10-29.tgz

Hey gang,

I just paid the X-Cart team to install the security-patch-2007-06-20.tgz for me, and I just wanted to know can someone please explain to me just what exactly this patch does? What is it for? I'm a novice to all of this and I'd like to understand what the purpose was for. Is it supposed to help protect X-Cart from hackers?

Thanks a lot!
Kevin
__________________
X-Cart
Business 5.3.3.4
The House of Mysterious Secrets
Reply With Quote
  #69  
Old 11-13-2007, 06:46 AM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: security-patch-2007-10-29.tgz

Yes, it fixes a possible exploit.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #70  
Old 11-13-2007, 07:05 AM
 
geckoday geckoday is offline
 

X-Wizard
  
Join Date: Aug 2005
Posts: 1,073
 

Default Re: security-patch-2007-10-29.tgz

Quote:
Originally Posted by kevinperson
Hey gang,

I just paid the X-Cart team to install the security-patch-2007-06-20.tgz for me, and I just wanted to know can someone please explain to me just what exactly this patch does? What is it for? I'm a novice to all of this and I'd like to understand what the purpose was for. Is it supposed to help protect X-Cart from hackers?

Thanks a lot!
Kevin
Yes, it is to help prevent against hackers. Input from the browser is often used in SQL statements to access the database. Hackers try specially crafted input using special characters (such as quotes) followed by their own SQL so that when put into an SQL statement in the program it terminates the intended SQL statement and runs theirs instead returning whatever information they want from the database. Programs must carefully validate input from the browser and/or escape it (convert special characters into things like \') to prevent this hijacking of SQL. X-Cart is fixing some specific instances where escaping isn't done when using browser input in SQL statements. They also added some generic system wide changes to minimize the possibility of such hacks being successful.
__________________
Manuka Bay Company
X-Cart Version 4.0.19 [Linux]

UGG Boots and other fine sheepskin products
http://www.snowriver.com
Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 12:22 PM.

   

 
X-Cart forums © 2001-2020