Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

Security bulletin 2009-12-02

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #11  
Old 02-13-2009, 11:15 AM
  BCSE's Avatar 
BCSE BCSE is online now
 

X-Guru
  
Join Date: Apr 2003
Location: Ohio - bcsengineering.com
Posts: 3,063
 

Default Re: Security bulletin 2009-12-02

Quote:
Originally Posted by Ene
The newsletter sending has been started. Since the script sends a fixed number of emails per hour it will take some time to send all the emails as we have many clients.

Got one of them now.

Carrie
__________________
Custom Development, Custom Coding and Pre-built modules for X-cart since 2002!

We support X-cart versions 3.x through 5.x!

Home of the famous Authorize.net DPM & CIM Modules, Reward Points Module, Point of Sale module, Speed Booster modules and more!


Over 200 X-cart Mods available & Thousands of Customizations Since 2002 - bcsengineering.com

Please E-Mail us for questions/support!
Reply With Quote
  #12  
Old 02-14-2009, 09:46 AM
  Jon's Avatar 
Jon Jon is offline
 

X-Guru
  
Join Date: Oct 2002
Location: Vancouver, Canada
Posts: 4,200
 

Default Re: Security bulletin 2009-12-02

Since there are many files other than the cc_ ps_ format, it would be really great to get a breakdown of the files in the payment folder and their usage. File permissions could then just be set to 000 until upgrading and then set back.
Reply With Quote
  #13  
Old 02-15-2009, 06:07 AM
 
georgewf georgewf is offline
 

Advanced Member
  
Join Date: Feb 2004
Posts: 76
 

Default Re: Security bulletin 2009-12-02 * Log Details *

Attached is the log of an attack in progress. I received notification of change in status of orders.

[10-Feb-2009 06:58:47] (shop: 10-Feb-2009 06:58:47) ORDERS message:
Login:
IP: 141.164.71.238
Operation: change status of orders (0) to 'F'
----
Request URI: /shop/payment/cc_basia.php
Backtrace:
/public_html/shop/include/func/func.order.php:1015
/public_html/shop/payment/cc_basia.php:176
-------------------------------------------------
Attached Files
File Type: txt log.txt (1.7 KB, 24 views)
__________________
xcart 4.7.7
Reply With Quote
  #14  
Old 02-16-2009, 06:21 PM
 
luis luis is offline
 

Member
  
Join Date: May 2005
Posts: 21
 

Default Re: Security bulletin 2009-12-02

I lookk for this file I could not find it xcart_dir>/payment/cc_basia.php

Why is that?

My version is 4.1.10
__________________
Luis
XCART Version 4.0.13
Reply With Quote
  #15  
Old 02-21-2009, 09:10 AM
 
elmirage001 elmirage001 is offline
 

X-Wizard
  
Join Date: Apr 2007
Posts: 1,964
 

Default Re: Security bulletin 2009-12-02

Quote:
Originally Posted by Ene
The newsletter sending has been started. Since the script sends a fixed number of emails per hour it will take some time to send all the emails as we have many clients.

Dear Ene,

FYI - I did not receive the newsletter until the 19th... Is there a way to speed up the process?

Thank you!
__________________
X-Cart GoldPlus v4.7.12 | reBOOT (reDUX) Template v4.7.12.9 | Always The Best
Reply With Quote
  #16  
Old 02-21-2009, 11:59 AM
 
cycloneuk cycloneuk is offline
 

Advanced Member
  
Join Date: Apr 2008
Posts: 54
 

Default Re: Security bulletin 2009-12-02

Quote:
Originally Posted by elmirage001
Dear Ene,

FYI - I did not receive the newsletter until the 19th... Is there a way to speed up the process?

Thank you!

Lucky you, i didn't get mine until this morning 21st February
__________________
X-Cart Gold 4.1.12
Reply With Quote
  #17  
Old 02-21-2009, 12:09 PM
  bigredseo's Avatar 
bigredseo bigredseo is offline
 

X-Man
  
Join Date: Oct 2002
Location: Omaha, NE, USA
Posts: 2,364
 

Default Re: Security bulletin 2009-12-02

OUCH!! That's way too long to be sitting with an exposed site! Definitely need to see about a program to send out emails faster. There's email regulation where you only send "X" mail per hour, but taking days to deliver is not good - weeks is even worse!
__________________
Conor Treacy - Big Red SEO - @bigredseo
Search Engine Optimization & Internet Marketing - We Bring Your Website Out Of Hiding!
If you can't be found on Google, Bing or Yahoo, you pretty much don't exist on the Internet.
Omaha SEO Office with National & Local SEO Services
Hourly Consulting - great for SEO Disaster Recovery, Audits and DIY Guidance
Reply With Quote
  #18  
Old 02-21-2009, 01:37 PM
 
carpeperdiem carpeperdiem is offline
 

X-Guru
  
Join Date: Jul 2006
Location: New York City, USA
Posts: 5,399
 

Default Re: Security bulletin 2009-12-02

I just received my notice today... fortunately, I read the forums.

Qualiteam should really consider using a 3rd party for security bulletin emails. The big-boy 3rd parties can send 10's of thousands of emails per hour. WITH open/bounce/unsubscribe tracking. AND google analytics integration. For very low $.
__________________
xcart 4.5.4 gold+ w/x-payments 1.0.6; xcart gold 4.4.4
Reply With Quote
  #19  
Old 02-21-2009, 02:39 PM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: Security bulletin 2009-12-02

Or better yet, how about a live update system IN X-Cart? Wordpress does it when there is a new release, and that is FREE software. Have an area for important messages on the home page of the admin, with links directly to the update kits/patches/etc. Simple and effective, and no one can claim they didn't see it or get the e-mail in their spam box.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #20  
Old 02-21-2009, 02:47 PM
 
carpeperdiem carpeperdiem is offline
 

X-Guru
  
Join Date: Jul 2006
Location: New York City, USA
Posts: 5,399
 

Default Re: Security bulletin 2009-12-02

Quote:
Originally Posted by balinor
Or better yet, how about a live update system IN X-Cart? Wordpress does it when there is a new release, and that is FREE software. Have an area for important messages on the home page of the admin, with links directly to the update kits/patches/etc. Simple and effective, and no one can claim they didn't see it or get the e-mail in their spam box.

vBulletin does the same thing. A "call home" tag that checks your version and if it's not the latest patch, vB will make it very clear that you have to patch...

I would imagine this is related to the vB call-home copy protection -- very well done/seamless to the admin.

I would support xcart if they implemented such a feature.
__________________
xcart 4.5.4 gold+ w/x-payments 1.0.6; xcart gold 4.4.4
Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 01:34 AM.

   

 
X-Cart forums © 2001-2020