Shopping Cart Software

Shopping Cart Software ClickCartPro XCS Version
corner image corner image

Massive security breach

Massive security breach

Postby Anbar » 30 Sep 2010 10:13

customers inputting personal details into the system when making accounts are being shown the previous users details.

what sort of half-arsed system is this CCP?

fix required, immediately.
Anbar
 
Posts: 236
Joined: 14 Jan 2010 19:08

Re: Massive security breach

Postby Dave » 30 Sep 2010 11:25

There are only 2 ways that could happen and neither of them is the fault of CCP nor can CCP do anything about it.

1. A shared computer that is not having cookies cleared after a person is done using it.

2. Hard coded links on the site that include a sid= value.
Dave
DynaComp Solutions ...Dynamic Computer Solutions for your business
Google Base Extension
Dave
 
Posts: 70
Joined: 06 Oct 2009 10:31

Re: Massive security breach

Postby Anbar » 30 Sep 2010 14:25

Dave wrote:There are only 2 ways that could happen and neither of them is the fault of CCP nor can CCP do anything about it.

1. A shared computer that is not having cookies cleared after a person is done using it.

2. Hard coded links on the site that include a sid= value.


user is in a different country to the other one, and 2) nope.

also:

trying to order some stuff off your site and it won't allow me to put in either the county or country, as soon as I go on to them they dissapear!


the more we see of CCP the worse it gets.
Anbar
 
Posts: 236
Joined: 14 Jan 2010 19:08

Re: Massive security breach

Postby robbiez » 30 Sep 2010 15:13

search on google for sid= site:antenocitisworkshop.com

and it will point you in the direction of the sid that has been hardcoded in your website and causing the problem.

You have got a few hardcoded links that include a different sid!!

As Dave said, it is nothing that is caused by CCP
robbiez
 
Posts: 16
Joined: 25 Mar 2010 17:35

Re: Massive security breach

Postby GreenbarnWeb » 30 Sep 2010 15:37

Hi
It is also worth checking any incoming links from say adwords that they do not contain links with sid= in them.
Howard Galpin
http://www.greenbarnweb.com
http://www.clickcartpro.co.uk - UK Customised version
http://www.clickcartpro.eu.com - European Customised version
GreenbarnWeb
Site Admin
 
Posts: 1155
Joined: 29 Jul 2009 10:58

Re: Massive security breach

Postby Dave » 30 Sep 2010 18:14

Anbar wrote:
trying to order some stuff off your site and it won't allow me to put in either the county or country, as soon as I go on to them they dissapear!


Answered in the other thread you started about this.
Dave
DynaComp Solutions ...Dynamic Computer Solutions for your business
Google Base Extension
Dave
 
Posts: 70
Joined: 06 Oct 2009 10:31

Re: Massive security breach

Postby Anbar » 30 Sep 2010 19:50

robbiez wrote:search on google for sid= site:antenocitisworkshop.com

and it will point you in the direction of the sid that has been hardcoded in your website and causing the problem.

You have got a few hardcoded links that include a different sid!!

As Dave said, it is nothing that is caused by CCP


means nothing to me whatsoever... translation into english please? What's an sid etc etc etc?
Or do I have to pay somebody for that?

The site is straight from Howard, so if anythings been hardcoded, he did it. (he'll deny it of course, he likes denying he has done things, even when you have a server log showing his IP logging in to screw your website: "It wasn't me" he will say.)
Last edited by Anbar on 30 Sep 2010 19:56, edited 1 time in total.
Anbar
 
Posts: 236
Joined: 14 Jan 2010 19:08

Re: Massive security breach

Postby Anbar » 30 Sep 2010 19:51

GreenbarnWeb wrote:Hi
It is also worth checking any incoming links from say adwords that they do not contain links with sid= in them.


we dont use adwords. :roll:

So, up to your usual standards of helpfullness really.

Random poster 1 Howard 0
Anbar
 
Posts: 236
Joined: 14 Jan 2010 19:08


Return to Configuration Help

Who is online

Users browsing this forum: No registered users and 0 guests

cron
corner image
Valid XHTML   Valid CSS   w3c wai aa
GreenbarnWeb.com © 2001 - 2013
corner image