Results 1 to 10 of 10
  1. #1
    Join Date
    Oct 2006
    Location
    Minnesota
    Posts
    10
    Plugin Contributions
    0

    Vulnerability Reports for Zen Cart.

    I found this web site that questions the vulnerability and security of Zen Cart.
    Thought it was interesting and I would pass it on.. Maybe it's something we can work on fixing.

    http://www.osvdb.org/searchdb.php?vu...&search=search

  2. #2
    Join Date
    Nov 2003
    Posts
    1,987
    Plugin Contributions
    15

    Default Re: Vulnerability Reports for Zen Cart.

    As far as I can see all those reports are about 1.3.0.2 or older versions. So I assume/hope upgrading to 1.3.6 should fix these problems.

  3. #3
    Join Date
    Nov 2003
    Posts
    1,155
    Plugin Contributions
    0

    Default Re: Vulnerability Reports for Zen Cart.

    What does "Status Stable" mean ?

  4. #4
    Join Date
    Jan 2004
    Posts
    66,450
    Plugin Contributions
    81

    Default Re: Vulnerability Reports for Zen Cart.

    Quote Originally Posted by paulm View Post
    As far as I can see all those reports are about 1.3.0.2 or older versions. So I assume/hope upgrading to 1.3.6 should fix these problems.
    PaulM is correct. The reported issues are all resolved and build-in to v1.3.5. Additional issues discovered by the Zen Cart team are included in v1.3.6.

    It is recommended to upgrade to v1.3.6 to enjoy the security benefits, as well as the many other features and improvements contained therein.
    .
    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    Jan 2004
    Posts
    66,450
    Plugin Contributions
    81

    Default Re: Vulnerability Reports for Zen Cart.

    Quote Originally Posted by DogTags View Post
    What does "Status Stable" mean ?
    "Status Stable" just means they've stopped mucking with the details of their report and are satisfied that they can stop flogging it to say how bad it is or isn't. Basically it's an indicator to hackers about whether it's worth going after or whether they should wait until the vulnerability is deemed "stable" in order to go for the bigger payload.
    Not exactly useful to anyone outside the "security vulnerability" industry.
    .
    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  6. #6
    Join Date
    Nov 2003
    Posts
    1,155
    Plugin Contributions
    0

    Default Re: Vulnerability Reports for Zen Cart.

    Thanks, Dr. :-)

  7. #7

    Default Re: Vulnerability Reports for Zen Cart.

    Quote Originally Posted by DrByte View Post
    "Status Stable" just means they've stopped mucking with the details of their report and are satisfied that they can stop flogging it to say how bad it is or isn't. Basically it's an indicator to hackers about whether it's worth going after or whether they should wait until the vulnerability is deemed "stable" in order to go for the bigger payload.
    Not exactly useful to anyone outside the "security vulnerability" industry.

    Sorry guys, i have to "VENT" on this one.....

    its crap like that we dont need. Im sure that anyone of the zenners here that actualy make a living with this system are sad to hear that not only are there hackers out there waiting for the "prime time" to attack someone/company, but there is a place that shows them WHEN this time is good, and also go into details about the issue itself to point you directly to the place needed to "hack" the confidential data.
    I already deal with fraudulant CC orders on a monthly basis!.(This is normal for my industry, and internet sales in general) I dont need the extra headache of wondering if someone is waiting to come take personal customer data which we hold so tight. Its horrable that is how our world works today...

    Sure that site has its plus for the fact that it shows you this information, (im hoping for the benifit of being able to secure it down) but personaly i think its rediculas... Its like showing the world how the OK city bombing was created/exicuted in specific detail..... GRRRRRRRR!!!! Why not just ask someone to do it again?!?!?!?

    Really the creators of this wonderfull system already know about issues and are always working hard to make sure they are rectified as quick as possable... So them -themselves dont really need this site to tell them where problems are... (this is why you donate to the team)....

    Again, i dont mean to offend anyone with this post, im just in shock that we have sites like this around.... its just asking for trouble IMO......
    Super Orders2
    Info at a glance
    export email address
    encrypted master pass
    quick updates
    recover carts
    order Tracking
    Tabbed products lite - admin edition
    Hosted with sashbox.net <- best host around...

  8. #8
    Join Date
    Oct 2006
    Location
    Minnesota
    Posts
    10
    Plugin Contributions
    0

    Default Re: Vulnerability Reports for Zen Cart.

    I agree with you about being outraged with malicious hackers..
    But the fact that that web site listed vulnerabilities is not nessasaraly a bad thing.. It helps with knowing the problem.. if you don't know what the problem is how do you know what needs to be fixed?

  9. #9
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: Vulnerability Reports for Zen Cart.

    I guess rather than post the issue and directions on exactly HOW to use the security exploit, it would be much better for these "security reporters" to QUIETLY let the developers of what ever software know.

    that way it can be fixed before the script kiddies read about HOW to break in
    Zen cart PCI compliant Hosting

  10. #10

    Default Re: Vulnerability Reports for Zen Cart.

    Quote Originally Posted by LokoLobo View Post
    I agree with you about being outraged with malicious hackers..
    But the fact that that web site listed vulnerabilities is not nessasaraly a bad thing.. It helps with knowing the problem.. if you don't know what the problem is how do you know what needs to be fixed?

    GARRANTEED,
    none of the creators of zencart need any site to inform them on what is wrong with the software... If they dont happen to find it themself, then rest assured- someone in the forums will bring it up....

    i believe the Merlin is right... it should be a more private thing....
    Super Orders2
    Info at a glance
    export email address
    encrypted master pass
    quick updates
    recover carts
    order Tracking
    Tabbed products lite - admin edition
    Hosted with sashbox.net <- best host around...

 

 

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg