Results 1 to 4 of 4
  1. #1
    Join Date
    Feb 2008
    Posts
    15
    Plugin Contributions
    0

    Default Ghost order problem or devious behavior?

    Last week we rolled a new ZenCart site into production running 1.3.7. We're using the Authorize.net AIM module for payments and it has migrated from Osc seamlessly.

    The site replaces an old OScommerce install.

    In an effort to not have overlapping orders with those of the past, using the instructions in the FAQ or a sticky post here, I modified an existing order to number 6000 and it successfully made the next real order 6001.

    Today around 8:00am this morning we had two new customers create accounts and place orders within minutes of each other. Here is what concerns me:

    Authorize.NET sent me two emails six minutes apart from each other confirming a receipt for a transaction. The first was for order #6002 for three items totaling $104.36. The second email was for order #6002 for one item totaling $3.23.

    In essence, Authorize.NET thinks both orders are #6002. So I went into the store and looked up the customer from the first order. There is no record of him ever purchasing anything, let alone three items for $100+

    Order 6002 does exist for customer #2 for the $3.23 item.

    We're using the purchase order mod, which puts an order into a queue to be dispatched to a supplier. Looking in the queue I see order #6001 (purchased over the weekend before all of this) and #6002 for the $3.23 item.

    There is literally no record of the three items being purchased, but the fact that Authorize.NET appears to have charged this individual's credit card and there is no order concerns me. Is it a bug? Is it a fluke with an order six minutes apart? Is it someone trying to exploit something and get free merchandise? (If so, it didn't work well, there is no record of the $100 order, so we'd never send it off to the supplier to drop ship)

    Has anyone seen this type of behavior? What should I do to determine what happened? Why is it even possible that these two individuals received the same exact order number?

  2. #2
    Join Date
    Feb 2008
    Posts
    15
    Plugin Contributions
    0

    Default Re: Ghost order problem or devious behavior?

    Ok. It looks like the buyer saw this:

    Code:
    1064 You have an error in your SQL syntax; check the manual that
    corresponds to your MySQL server version for the right syntax to use near
    's(qty: 1) + Denim Shirt, Women's(qty: 1) + Sport Shirt(qty: 1) [Date] =>
    Fe' at line 1
    Is it the comma or the single quotes that are breaking these items?

  3. #3
    Join Date
    Jun 2003
    Posts
    33,721
    Plugin Contributions
    0

    Default Re: Ghost order problem or devious behavior?

    Is it the comma or the single quotes that are breaking these items?
    Yes, there is a patch posted elsewhere on the forum.
    Please do not PM for support issues: a private solution doesn't benefit the community.

    Be careful with unsolicited advice via email or PM - Make sure the person you are talking to is a reliable source.

  4. #4
    Join Date
    Jan 2004
    Posts
    66,450
    Plugin Contributions
    81

    Default Re: Ghost order problem or devious behavior?

    Quote Originally Posted by jgarvas View Post
    Last week we rolled a new ZenCart site into production running 1.3.7. We're using the Authorize.net AIM module for payments
    The "apostrophe" bug and duplicate-order-number issue were fixed in v1.3.8.
    As Kim mentioned, there is a partial backport for 1.3.7 compatibility available here: http://www.zen-cart.com/forum/showth...023#post441023

    As an aside, you should plan an upgrade ... there's a years' worth of fixes and improvements in 1.3.8a that aren't in 1.3.7.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

 

 

Similar Threads

  1. v139h Help sudden loss of order's comments and odd behavior
    By freedude in forum General Questions
    Replies: 10
    Last Post: 4 Oct 2014, 12:07 AM
  2. Ghost zc_install in SSL??
    By RuFuS in forum Installing on a Linux/Unix Server
    Replies: 4
    Last Post: 4 Nov 2007, 09:37 PM
  3. Ghost Characters
    By reaganshirt in forum Setting Up Categories, Products, Attributes
    Replies: 1
    Last Post: 23 Jun 2006, 05:47 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg