Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

Security bulletin 2008-12-18

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #51  
Old 12-30-2008, 11:49 PM
  Ene's Avatar 
Ene Ene is offline
 

X-Cart team
  
Join Date: Aug 2004
Posts: 907
 

Default Re: Security bulletin 2008-12-18

Quote:
Most distributions by other companies would have an extension on the end of the version number to denote additional changes

Even putting a unix timestamp may be helpful, or just a date:
4.2.0-1230661200 = 12/30/2008 18:20
OR
4.2.0-12302008 or just 4.2.0-1230

Definitely if changes are being made to an archive, that can create serious issues (even from bug tracking point of view.

HelpDesk file area.
Attached Images
File Type: png file_area.png (9.1 KB, 49 views)
__________________
Eugene Kaznacheev,
Evangelist/Product Manager at Ecwid: http://www.ecwid.com/ (since Sept 2009)

ex-Head of X-Cart Tech Support Department
ex- X-Cart Hosting Manager - X-Cart hosting
ex-X-Cart Technical Support Engineer


Note: For the official guaranteed tech support services please turn to the Customers HelpDesk.
Reply With Quote
  #52  
Old 12-31-2008, 03:17 PM
 
Chris B Chris B is offline
 

eXpert
  
Join Date: Oct 2002
Posts: 226
 

Default Re: Security bulletin 2008-12-18

Hi Ene,

The dates within the support helpdesk file download area have dates not related to the release dates. I noticed that last week when I was checking to make sure all patches were applied to each version we use.

Many say January 10, 08 even though they are patches from 2006.

ScreenShot Attached

Chris
Attached Images
File Type: jpg screenprint.jpg (212.0 KB, 27 views)
__________________
4.0x - 4.5x
Reply With Quote
  #53  
Old 01-01-2009, 07:58 AM
  bigredseo's Avatar 
bigredseo bigredseo is offline
 

X-Man
  
Join Date: Oct 2002
Location: Omaha, NE, USA
Posts: 2,364
 

Default Re: Security bulletin 2008-12-18

Hello Eugene,

I was referring to the actual RELEASE scripts, not the patches.

If the script available for download on 12/29 is different from that which was available on 10/9, there should be indication to the user that patches have been applied (or bug fixes), and that the original 10/9 script they downloaded is now incomplete compared to the release available on 12/29.
__________________
Conor Treacy - Big Red SEO - @bigredseo
Search Engine Optimization & Internet Marketing - We Bring Your Website Out Of Hiding!
If you can't be found on Google, Bing or Yahoo, you pretty much don't exist on the Internet.
Omaha SEO Office with National & Local SEO Services
Hourly Consulting - great for SEO Disaster Recovery, Audits and DIY Guidance
Reply With Quote
  #54  
Old 01-02-2009, 11:36 AM
  gb2world's Avatar 
gb2world gb2world is offline
 

X-Wizard
  
Join Date: May 2006
Location: Austin, TX
Posts: 1,970
 

Default Re: Security bulletin 2008-12-18

Hi Eugene -

Maybe this will help to make the issue clearer:

Are the security patches provided for 4.1.11 applicable to any version of the 4.1.11 distribution?

For example - I have a 4.1.11 instance which was created from an upgrade patch for 4.1.10->4.1.11 downloaded in early September. I did a diff of the file versions of my cart to a current 4.1.11 cart - There are over 100 files which have been updated since I upgraded. Can the patch be applied with confidence, or are any of the other changes also required?

I have other 4.1.11 instances which have different file versions, depending upon when I downloaded them.

I also have a 4.1.9 instance of XCART - but I don't think I have a way to compare it to what is your latest 4.1.9 release. Is it possible to publish a versions file for previous 4.1.x distributions?
__________________
X-CART (4.1.9,12/4.2.2-3/4.3.1-2/4.4.1-5)-Gold
(CDSEO, Altered-Cart On Sale, BCSE Preorder Backorder, QuickOrder, X-Payments, BCSE DPM Module)
Reply With Quote
  #55  
Old 01-05-2009, 01:59 AM
  Ene's Avatar 
Ene Ene is offline
 

X-Cart team
  
Join Date: Aug 2004
Posts: 907
 

Default Re: Security bulletin 2008-12-18

Quote:
The dates within the support helpdesk file download area have dates not related to the release dates. I noticed that last week when I was checking to make sure all patches were applied to each version we use.

Sometimes the security patches can be re-uploaded later. For example due to reorganisation of the File Area folders.

Quote:
Are the security patches provided for 4.1.11 applicable to any version of the 4.1.11 distribution?

Yes.
We do not change the distribution packs once we upload them. So X-Cart 4.1.11 you downloaded one month earlier and 4.1.11 you've downloaded today are the same.

Quote:
Can the patch be applied with confidence, or are any of the other changes also required?

If you upgrdaded your store correctly, you can apply the patch without any worries.

Quote:
I also have a 4.1.9 instance of XCART - but I don't think I have a way to compare it to what is your latest 4.1.9 release. Is it possible to publish a versions file for previous 4.1.x distributions?

As I said before you should just download the security patch for 4.1.9 version and apply it.
__________________
Eugene Kaznacheev,
Evangelist/Product Manager at Ecwid: http://www.ecwid.com/ (since Sept 2009)

ex-Head of X-Cart Tech Support Department
ex- X-Cart Hosting Manager - X-Cart hosting
ex-X-Cart Technical Support Engineer


Note: For the official guaranteed tech support services please turn to the Customers HelpDesk.
Reply With Quote
  #56  
Old 01-07-2009, 10:28 PM
  beetlejuice's Avatar 
beetlejuice beetlejuice is offline
 

eXpert
  
Join Date: Apr 2007
Posts: 251
 

Default Re: Security bulletin 2008-12-18

from post #47

Well I'm no closer to finding the real solution. I submitted one of the prepare.php 4.1.9 files to QT and they replied that it hadn't had any patches applied so I would need to install each one after downloading from the file area. Did that and it worked fine, however trying to patch the prepare.php on another 4.1.9 store was impossible as it was missing too many lines of code, and from what I could gather looked more like a 4.1.10 prepare.php than a 4.1.9. So I downloaded the 4.1.10 security patches and they seemed to be Ok for the prepare.php changes. And before you jump, it is definitely a 4.1.9 store (well according to the patch/upgrade area in admin). The store works fine so I'm going to load a backup of XCart downloads I made some time ago and check to see if there are any variations between those downloads and the ones currently available from XCart's download area.

At least the stores are patched finally.
__________________
XCart 4.5.4, 4.6.1, 4.64 stores
Many, many mods from Altered Cart
XCart Mods Reboot template
The XCart Store Templates and Mods
WCM CDSEO Pro
BCSE Rewards Points and Gallery Mods
and a few others
Reply With Quote
  #57  
Old 01-08-2009, 03:54 AM
  JWait's Avatar 
JWait JWait is offline
 

X-Man
  
Join Date: Nov 2005
Location: California
Posts: 2,440
 

Default Re: Security bulletin 2008-12-18

"it is definitely a 4.1.9 store (well according to the patch/upgrade area in admin)"

You can't really trust that. I think all it does is compare what it says in the VERSION file with what it says in the xcart_config table for the "version". If they are wrong, but both say the same thing you would never know it.
__________________
Two Separate X-Cart Stores
Version 4.4.4 Gold - X-AOM - Vivid Dreams Aquamarine (modified) - Linux
Mods - Newest Products - View All -, and a few others. Numerous upgrades from 4.0.x series.
Integrated with Stone Edge Order Manager + POS

Version 4.1.12 Gold (fresh install) - X-AOM - Linux
Mods - XCSEO free
Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 04:45 AM.

   

 
X-Cart forums © 2001-2020