Thread: Why bother?

Results 1 to 7 of 7
  1. #1
    Join Date
    Feb 2007
    Posts
    25
    Plugin Contributions
    0

    Default Why bother?

    What I don't see anywhere is a list of reasons why I should go to the trouble of upgrading from my seemingly stable 1.3.8a to 1.3.9h. What I do see is a list of convoluted and time-consuming steps, which may or may not cause a lot of headaches and loss of customisations.

    What compelling reasons are there to go to the effort of upgrading from 1.3.8a to 1.3.9h?

    Cheers.

  2. #2
    Join Date
    Dec 2009
    Location
    Amersfoort, The Netherlands
    Posts
    2,846
    Plugin Contributions
    25

    Default Re: Why bother?

    How about safer shopping for your customers, and less risk of being hacked

  3. #3
    Join Date
    Jun 2005
    Location
    Cumbria, UK
    Posts
    10,263
    Plugin Contributions
    3

    Default Re: Why bother?

    1.3.8 has some serious vulnerabilities. This is NOT because it was a badly developed version, only that there is a constant game of leap-frog between the criminal hacking community, and the developers of software.

    As soon as an exploit is developed by hackers and discovered to be in the public domain, responsible software developers work at blocking it.

    Hence the constant upgrades and improvements.

    Additionally, as operating software improves (php, MySql, Linux and Apache), so the user platform software should also upgrade in tandem.

    You are running a severe risk of hacking if you persist with 1.3.8 - and believe me, it is a difficult, time-consuming and EXPENSIVE job to fix things after a hack.

    Upgrading from 1.3.8 to 1.3.9h is relatively quick. MOST add-on modules that work on 1.3.8 will function on 1.3.9, but you will need to do some checking.
    20 years a Zencart User

  4. #4
    Join Date
    Jul 2005
    Location
    Upstate NY
    Posts
    22,010
    Plugin Contributions
    25

    Default Re: Why bother?

    Even if you have applied the security patches, v1.3.8a is vulnerable to a dedicated hacker, and if you haven't, any script kiddie can break into your store. There are no known security vulnerabilities in v1.3.9h.

  5. #5
    Join Date
    Nov 2009
    Location
    UK
    Posts
    1,090
    Plugin Contributions
    0

    Default Re: Why bother?

    IMO The best security patch for any Zencart is password protecting your admin directory at a server level..

    ..ironically if you look at any of the Zencart hack scripts on the public domain, they all check if the admin directory has changed its name, or is password protected. If its a yes to any of these, the script ends.

  6. #6
    Join Date
    Feb 2007
    Posts
    25
    Plugin Contributions
    0

    Default Re: Why bother?

    My admin area is moved, of course. I might password it too after reading this thread. My front-end makes heavy use of url rewriting, which also has the benefit of protecting against a lot of the dodgy requests that are sent.

    If there was a clear bug list somewhere that showed what was fixed in each version, or highlighted the main issues with each, then it might help. What is wrong with 1.3.8a that I need to seriously worry about?

  7. #7
    Join Date
    Dec 2009
    Location
    Amersfoort, The Netherlands
    Posts
    2,846
    Plugin Contributions
    25

    Default Re: Why bother?

    There is.
    If you go to http://www.zen-cart.com/forum/forumdisplay.php?f=2 you can read all the threads about the 1.39 releases and the fixes that were done, both bugs and security

 

 

Similar Threads

  1. Spot of bother iwth a couple of products
    By bottyz in forum General Questions
    Replies: 4
    Last Post: 16 Nov 2010, 05:47 PM
  2. I hate to bother everyone....
    By suehigman in forum Templates, Stylesheets, Page Layout
    Replies: 13
    Last Post: 27 Jan 2009, 10:45 PM
  3. Why?! Why?! Why?! (IE6 causing links to disappear instead of setting color)
    By pholli4 in forum Templates, Stylesheets, Page Layout
    Replies: 1
    Last Post: 10 May 2008, 07:57 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR