Page 1 of 2 12 LastLast
Results 1 to 10 of 11
  1. #1
    Join Date
    Oct 2005
    Location
    Chicago, IL USA
    Posts
    1,557
    Plugin Contributions
    28

    Default Customer address data security patch

    Thank you to the Zen Cart team and the other contributors for finding and fixing this issue.

    Two questions, after installing the patch and running the SQL patch.

    1. The spam customer records are not deleted. Just curious to know why? The leave an audit trail? Less risk to just disable the thread but not delete?
    2. The clean up check page still reports spam accounts after running the patch. I still get the "80 statement(s) processed" message. Is that to be expected?

  2. #2
    Join Date
    Sep 2009
    Location
    Stuart, FL
    Posts
    12,501
    Plugin Contributions
    88

    Default Re: Customer address data security patch

    They're not removed to, as indicated, keep the audit-trail but also to keep the database-schema 'intact'.

    I'm guessing that the message you refer to is coming from the Install SQL Patches tool, correct? If so, that's to be expected.

  3. #3
    Join Date
    Sep 2009
    Location
    Stuart, FL
    Posts
    12,501
    Plugin Contributions
    88

    Default Re: Customer address data security patch

    Note, too, that the checker-tool simply looks for any changes made by the SQL script and reports if any such changes were made.

  4. #4
    Join Date
    Oct 2005
    Location
    Chicago, IL USA
    Posts
    1,557
    Plugin Contributions
    28

    Default Re: Customer address data security patch

    Quote Originally Posted by lat9 View Post
    They're not removed to, as indicated, keep the audit-trail but also to keep the database-schema 'intact'.

    I'm guessing that the message you refer to is coming from the Install SQL Patches tool, correct? If so, that's to be expected.
    Thanks for confirming #1

    I think my second question was confusing. Let me clarify. After running the SQL patch, the file 'spam_cleanup_check.php' uploaded to the admin folder is still reporting spam accounts.

    Having said that, I see the file is looking for four specific pieces of text, so very likely it's a false positive. On one site, I see a valid customer with fake###################### as the email address. The rest of the record looks like a simple test custom account.

  5. #5
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Customer address data security patch

    The patch zip files have been updated to fix the spam_cleanup_check.php false-positives.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  6. #6
    Join Date
    Oct 2005
    Location
    Chicago, IL USA
    Posts
    1,557
    Plugin Contributions
    28

    Default Re: Customer address data security patch

    Quote Originally Posted by DrByte View Post
    The patch zip files have been updated to fix the spam_cleanup_check.php false-positives.
    Thank you!!

  7. #7
    Join Date
    Dec 2022
    Location
    UK
    Posts
    2
    Plugin Contributions
    0

    Default Re: Customer address data security patch

    Hi, I'm running 1.5.8a and do not have a includes/functions/database.php file to replace. Should I just add the new file or do I have other issues?

  8. #8
    Join Date
    Feb 2006
    Location
    Tampa Bay, Florida
    Posts
    9,704
    Plugin Contributions
    123

    Default Re: Customer address data security patch

    There should be a file called `includes/functions/database.php` starting from the root of your shop. This is not under the admin, this is a storefront file.
    That Software Guy. My Store: Zen Cart Modifications
    Available for hire - See my ad in Services
    Plugin Moderator, Documentation Curator, Chief Cook and Bottle-Washer.
    Do you benefit from Zen Cart? Then please support the project.

  9. #9
    Join Date
    Dec 2022
    Location
    UK
    Posts
    2
    Plugin Contributions
    0

    Default Re: Customer address data security patch

    Thanks for the speedy reply.

    There is definitely no database.php file in /public_html/includes/functions folder.

    However I do have one in my /public_html/admin***/includes/functions folder.

  10. #10
    Join Date
    Sep 2009
    Location
    Stuart, FL
    Posts
    12,501
    Plugin Contributions
    88

    Default Re: Customer address data security patch

    Quote Originally Posted by att_mike View Post
    Thanks for the speedy reply.

    There is definitely no database.php file in /public_html/includes/functions folder.

    However I do have one in my /public_html/admin***/includes/functions folder.
    Are you sure you're running on zc158a? That release (a) has /includes/functions/database.php and (b) does not have an admin/includes/functions/database.php.

    I'm having a hard time envisioning a zc158a storefront that's not going to whitescreen without that storefront function file.

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. Patch: PHPMailer security patch (Dec 2016) for v155c and older
    By DrByte in forum Zen Cart Release Announcements
    Replies: 3
    Last Post: 12 Apr 2017, 08:44 PM
  2. Security patch?
    By Cindy2010 in forum General Questions
    Replies: 1
    Last Post: 28 Aug 2010, 02:23 AM
  3. Replies: 15
    Last Post: 2 Oct 2009, 11:45 AM
  4. Security Patch
    By Snotori in forum General Questions
    Replies: 1
    Last Post: 2 Sep 2006, 06:34 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR