Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

POODLE vulnerability in SSLv3

 
Reply
   X-Cart forums > X-Payments > X-Payments issues & questions
 
Thread Tools
  #71  
Old 10-30-2014, 10:44 PM
 
donmck donmck is offline
 

Senior Member
  
Join Date: Dec 2005
Location: Australia
Posts: 137
 

Default Re: POODLE vulnerability in SSLv3

Quote:
Originally Posted by aim
X-Cart works properly with the last
curl 7.38.0
libcurl/7.38.0
OpenSSL/1.0.1j
libs

So you have to upgrade to CentOS 6 as advised.

Please take into account Intershipper issues for the last curl/OpenSSL libs
http://us1.campaign-archive2.com/?u=8f406bcb33564cce3343fee6e&id=7b9a827fc0&e=[UNIQID]

Thanks Ildar,

however I have no idea if this is in my xcart software, or on my server software, and no idea how to proceed to upgrade to CentOS 6

Could you please tel me what action I should be taking to get this corrected.

Cheers Don...
__________________
Don McKenzie

http://www.dontronics-shop.com/
X-Cart 4.0.17 [Unix]

█ Hosting by www.totalserversolutions.com The very best home for your X-Cart. (was ewdhosting.com)
Reply With Quote
  #72  
Old 10-30-2014, 11:36 PM
  rocky's Avatar 
rocky rocky is offline
 

X-Cart team
  
Join Date: Jul 2005
Posts: 719
 

Default Re: POODLE vulnerability in SSLv3

Quote:
Originally Posted by donmck
Thanks Ildar,

however I have no idea if this is in my xcart software, or on my server software, and no idea how to proceed to upgrade to CentOS 6

Could you please tel me what action I should be taking to get this corrected.

Cheers Don...


It's a server software. You should contact your hosting admin and ask them to upgrade OS on the server to the latest version.

Thank you.
__________________
Alexander Dyachkov,
Director of Customer Success

Last edited by rocky : 10-30-2014 at 11:40 PM.
Reply With Quote
  #73  
Old 10-30-2014, 11:45 PM
 
donmck donmck is offline
 

Senior Member
  
Join Date: Dec 2005
Location: Australia
Posts: 137
 

Default Re: POODLE vulnerability in SSLv3

Quote:
Originally Posted by rocky
It's a server software. You should contact your hosting admin and ask them to upgrade OS on the server to the latest version.

Thank you.

Thank you Alexander. I update the server OS software to CentOS 6, and the existing Xcart V4.0.17 should run, correct?

Cheers Don...
__________________
Don McKenzie

http://www.dontronics-shop.com/
X-Cart 4.0.17 [Unix]

█ Hosting by www.totalserversolutions.com The very best home for your X-Cart. (was ewdhosting.com)
Reply With Quote
  #74  
Old 10-31-2014, 12:06 AM
  rocky's Avatar 
rocky rocky is offline
 

X-Cart team
  
Join Date: Jul 2005
Posts: 719
 

Default Re: POODLE vulnerability in SSLv3

Quote:
Originally Posted by donmck
Thank you Alexander. I update the server OS software to CentOS 6, and the existing Xcart V4.0.17 should run, correct?

Cheers Don...


If MySQL/PHP versions won't be changed then everything should be working well.

In any case, I'd recommend you to check whether PHP5/MySQL5 compatibility patches are applied to your store.

You may also contact our support team via HelpDesk so that we could help you:

https://secure.x-cart.com

Thank you.
__________________
Alexander Dyachkov,
Director of Customer Success
Reply With Quote
  #75  
Old 10-31-2014, 12:12 AM
 
donmck donmck is offline
 

Senior Member
  
Join Date: Dec 2005
Location: Australia
Posts: 137
 

Default Re: POODLE vulnerability in SSLv3

Quote:
Originally Posted by rocky
If MySQL/PHP versions won't be changed then everything should be working well.

In any case, I'd recommend you to check whether PHP5/MySQL5 compatibility patches are applied to your store.

You may also contact our support team via HelpDesk so that we could help you:

https://secure.x-cart.com

Thank you.

OK, thanks very much Alexander

Cheers Don...
__________________
Don McKenzie

http://www.dontronics-shop.com/
X-Cart 4.0.17 [Unix]

█ Hosting by www.totalserversolutions.com The very best home for your X-Cart. (was ewdhosting.com)
Reply With Quote
  #76  
Old 10-31-2014, 06:51 AM
  BCSE's Avatar 
BCSE BCSE is offline
 

X-Guru
  
Join Date: Apr 2003
Location: Ohio - bcsengineering.com
Posts: 3,091
 

Default Re: POODLE vulnerability in SSLv3

Quote:
Originally Posted by Ksenia
*AuthorizeNet - CIM (in older X-Cart versions through 4.4.5).

We're confused why your post states CIM? X-cart does not have CIM in it. The Authorize.net CIM module is one we built and is not affected.

Thanks,

Carrie
__________________
Custom Development, Custom Coding and Pre-built modules for X-cart since 2002!

We support X-cart versions 3.x through 5.x!

Home of the famous Authorize.net DPM & CIM Modules, Reward Points Module, Point of Sale module, Speed Booster modules and more!


Over 200 X-cart Mods available & Thousands of Customizations Since 2002 - bcsengineering.com

Please E-Mail us for questions/support!
Reply With Quote
  #77  
Old 10-31-2014, 03:24 PM
 
risabb risabb is offline
 

Advanced Member
  
Join Date: Mar 2007
Posts: 75
 

Default Re: POODLE vulnerability in SSLv3

YogaHub,

I have version 4.0.19 and could not find the xpc_func.php file either. I was using Dreamweaver to connect to the server. However, when I used FileZilla to FTP to the server, I DID see that file.

Risa
__________________
Risa
X-Cart ver. 4.0.19 GOLD
Reply With Quote
  #78  
Old 11-01-2014, 10:20 AM
  moonslice's Avatar 
moonslice moonslice is offline
 

Senior Member
  
Join Date: May 2004
Posts: 128
 

Default Re: POODLE vulnerability in SSLv3

Using: x-cart 4.4.5 with shared ssl cert.

We did update cPanel to latest version and blocked sslv3 and now...

If I click on any of the 'Recommended Products' it brings up a

406 Not Acceptable page
==========================
An appropriate representation of the requested resource /shop/product.php could not be found on this server.
Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
==========================

And then I can't click on any other product (only https secure pages work) until I remove all cookies related to the site.

It's not related to sslv3 patch as this problem happens whether or not patch was applied.

What can I do to fix this?
__________________
Jim - X-cart Gold 4.4.5
Reply With Quote
  #79  
Old 11-01-2014, 02:30 PM
  cherie's Avatar 
cherie cherie is offline
 

X-Wizard
  
Join Date: May 2003
Location: USA
Posts: 1,534
 

Default Re: POODLE vulnerability in SSLv3

Quote:
Originally Posted by moonslice
An appropriate representation of the requested resource /shop/product.php could not be found on this server
That sounds like what you might see from a mod_security filter. You might want to check with your host.
__________________
redlimeweb.com
custom mods and design integration
4.7 linux
Reply With Quote
  #80  
Old 11-01-2014, 02:34 PM
  moonslice's Avatar 
moonslice moonslice is offline
 

Senior Member
  
Join Date: May 2004
Posts: 128
 

Default Re: POODLE vulnerability in SSLv3

Thanks cherie!

But... all of the carts are on the same server, and it's only blocking that one page on one cart. Does that make sense it would still be the mod_security?
__________________
Jim - X-cart Gold 4.4.5
Reply With Quote
Reply
   X-Cart forums > X-Payments > X-Payments issues & questions



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 05:30 AM.

   

 
X-Cart forums © 2001-2020