Results 1 to 3 of 3
  1. #1
    Join Date
    Sep 2013
    Location
    in the clouds
    Posts
    33
    Plugin Contributions
    0

    Default Is my surfing behavior vulnerable to XSS attacks?

    Hello, I would like some insights on XSS / security concerns while having the admin section of your site open and viewing other 'trusted' websites at the same time. I understand that as a rule, one should never have an active admin login session while viewing other websites in a different tab.

    That being said, I have never surfed any other website while being logged in to the admin and used a different window of the same browser (Chrome), but there are occasions where I have had to look at other websites (competitors and suppliers websites) while being logged in. Is this safe if I am using one browser (Chrome) to have an active admin login session and another browser (Firefox or IE) to be logged into a suppliers website?

    Or am I still "handling raw chicken and licking your fingers" (http://www.zen-cart.com/wiki/index.p...ecommendations)

    Many thanks, Izzy.

  2. #2
    Join Date
    Jan 2004
    Posts
    66,446
    Plugin Contributions
    81

    Default Re: Is my surfing behavior vulnerable to XSS attacks?

    It would be foolish of me to say "don't worry, it'll be fine", because I have no idea what your website surfing behaviors are like, nor how you've changed or added to your site's ZC core code in ways that might break the built-in security protections. So I have to give you the safe answer:

    You should follow the "general rule" to "not surf other sites with an active Admin session open in the same browser". That's just plain safe practice.

    That said, Zen Cart goes to great lengths to prevent typical XSS and CSRF risks, especially in the latest version (v1.5.3 is even better than 1.5.1 was in this area).

    But, no matter how smart ZC is, if you're surfing sites that could be prone to launching XSS attacks against you, then you owe it to yourself to make some changes and practice safe computing behaviors.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Sep 2013
    Location
    in the clouds
    Posts
    33
    Plugin Contributions
    0

    Default Re: Is my surfing behavior vulnerable to XSS attacks?

    hello. I was hoping this would be safe. LOL I guess I best get down to PC World and pick up a 2nd laptop. Planning to update to 1.5.3 in the next few months :)

 

 

Similar Threads

  1. PHP versions prior to 5.3.12 and 5.4.2 are vulnerable.
    By jetx in forum General Questions
    Replies: 7
    Last Post: 10 Apr 2014, 06:40 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg