AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
January 07, 2009, 12:47:03 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 5329 Members
Latest Member: ErereGatNeT
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Topic: Serious OSCommerce Security Issue 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Serious OSCommerce Security Issue  (Read 468 times)
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
Serious OSCommerce Security Issue
« on: July 09, 2005, 11:47:15 PM »

Today, through a glitch in some changes we made to a client's OSCommerce setup, we discovered a very serious issue with security in OSCommerce.  Because I have just done an extensive search and not seen this issue reported, I won't go in to details.  But the end result is that it is VERY easy for someone with virtually NO hacking expetise to have acccess to OSCommerce admin area.

We will be working with some security modules over the next few days to see if these have any impact on this issue, and I just reported it to the OSCommerce team.  In the meantime, I am going to quote here a post over on the OSCommerce forums:

1. If you are going to use the standard administration system, LOCK IT DOWN and change the default directory.
2. Install a template mod... I know thats not very security oriented but you will understand....
3. As far as the latest milestone, for my current version, i took the last stable release and spent about 10 hours playing with various contributions from this site, Almost anything you can think of you can get from here. Though, the administration security module i build from scratch, you can find a plethra in the contribution pages.
4. Secure all your directories, and do not run phpmyadmin on the Live server.
5. The most important thing, learn the code, live the code....be one with the code.
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Topic: Serious OSCommerce Security Issue « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!