Results 1 to 9 of 9
  1. #1
    Join Date
    Jan 2007
    Posts
    17
    Plugin Contributions
    0

    Default How could this happen?

    A client received the following email from a customer:

    > Hello, my name is ABC, and I went to make an order today and
    > when I made the order, I realized I was somehow logged on to
    > someone else's account (???). Wish I had paid more attention while
    > making the order. I am concerned about this for privacy issues,
    > obviously. From what I remember, the account was that of a XYZ.
    > This greatly worries me. Probably not a whole lot that
    > can be done now, but any help/insight would be appreciated. Thanks.

    ABC was a new customer and XYZ's account was over a year old. ABC's order was placed as XYZ's - as is mentioned above. XYZ had placed and order a half hour before ABC placed his and the order ids are consecutive.

    ABC was using his own laptop and internet connection.

    Strange, eh? Any ideas?

    Thanks!

  2. #2
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: How could this happen?

    ask them WHERE they hit the link from,
    how did they get to the site,
    its possible and probable that they came from a link with a zen ID attached to it
    Zen cart PCI compliant Hosting

  3. #3
    Join Date
    Jan 2007
    Posts
    17
    Plugin Contributions
    0

    Default Re: How could this happen?

    Interesting thought - I'll check the logs, but for that to happen wouldn't XYZ have to send ABC a link? It's my understanding that ABC and XYZ don't know each other.

    How else could a link with someone's zen ID be "out there". How would a link with a zen ID be in a URL? It's a cookie, right?

  4. #4
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: How could this happen?

    If someone Sends a link
    or copies and pasts a link somewhere,
    it happens all the time,
    make sure to set spider sessions to false,
    Zen cart PCI compliant Hosting

  5. #5
    Join Date
    Jan 2005
    Location
    USA, St. Louis
    Posts
    3,710
    Plugin Contributions
    9

    Default Re: How could this happen?

    Quote Originally Posted by pbo808 View Post
    Interesting thought - I'll check the logs, but for that to happen wouldn't XYZ have to send ABC a link? It's my understanding that ABC and XYZ don't know each other.

    How else could a link with someone's zen ID be "out there". How would a link with a zen ID be in a URL? It's a cookie, right?
    XYZ could have posted in a forum about the some great deal at your site, and the link had the zenid in it. ABC clicks the link, your site things ABC is XYZ. The zen id is in the link upon the person's first visit to the site, then it goes away. A lot of times, the very own store owner posts a link with a zen id in a forum, then there's a TON of issues.

  6. #6
    Join Date
    Jan 2007
    Posts
    17
    Plugin Contributions
    0

    Default Re: How could this happen?

    I do see some zenid entries in the apache log file - including some from Google referrers.

    What would cause the zenid to be in the URL? I noticed that when I browse the site using Firefox on Ubuntu (feisty) there are no zenids in the urls even when I'm logged in. If a user has cookies disabled?

  7. #7
    Join Date
    Jan 2007
    Posts
    17
    Plugin Contributions
    0

    Default Re: How could this happen?

    Prevent Spider Sessions is true, but Force Cookie Use is false. Should Force Cookie Use be set to true?

  8. #8
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: How could this happen?

    Leave the cookie-use settings alone.

    Set Recreate Session to true if you want to prevent folks from coming in on re-used zenid links.

    The most common cause of zenid links getting posted is ... someone does a copy/paste from the site onto an email or a blog etc. Not necessarily you ... perhaps someone fond of your products, sharing the links with a friend.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  9. #9
    Join Date
    Jan 2007
    Posts
    17
    Plugin Contributions
    0

    Default Re: How could this happen?

    Thanks for the reply DrByte... I'll check into the Recreate Session param.

 

 

Similar Threads

  1. Header off center???? How did this happen?
    By jenkins2212 in forum Templates, Stylesheets, Page Layout
    Replies: 9
    Last Post: 16 Feb 2014, 05:43 PM
  2. How hard could this layout be?
    By dainteegurl in forum Templates, Stylesheets, Page Layout
    Replies: 3
    Last Post: 1 Nov 2009, 06:28 PM
  3. How can I make this happen?
    By NJ2NC06 in forum General Questions
    Replies: 2
    Last Post: 2 Nov 2008, 10:25 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR