Results 1 to 8 of 8
  1. #1
    Join Date
    Aug 2004
    Location
    Newport, Wales
    Posts
    283
    Plugin Contributions
    0

    Default Customers details apparently on View

    Hi

    Just had a frealed out customer phone up saying her customer account had been hacked and she has had to cancel all her credit cards.

    The scenario is as follows - another customer visited our site and when she found something she liked she added it to her basket ready to create an account whereupon it immediately took this customer into the other customers account.

    This customer who could see the other customers info mailed her telling her how she got her email address and why she was mailing

    She ended by saying

    >As i work in new media i realise just how very poor security this is
    >and am
    >worried for your personal details. Of course i logged out and didn't place
    >the order as it would have a) been on your account and b) i now don't trust
    >the site and will get the gift from elsewhere.

    Any idea how I can varify if this actually happened and if so why

    More bad news is that the site is still using 1.2.6 (???? i have just noticed that in admin it says that the Version of Zen Cart appears to be Current ............something is seriously wrong here !)

    Any help would be appreciated

    Cheers
    Brinley

  2. #2
    Join Date
    Jul 2006
    Posts
    90
    Plugin Contributions
    0

    Default Re: Customers details apparently on View

    I have noticed something very similar while using the who's online tool. Ocassionally when clicking on the same product that the customer is looking at, from within admin; i am actually logged into the customers account and can see all their account details!!

    I have searched the forums but havent found anything like this posted by anybody else until now. BTW. Im using 1.3.02

  3. #3
    Join Date
    May 2006
    Location
    Texas
    Posts
    565
    Plugin Contributions
    4

    Default Re: Customers details apparently on View

    this is normal.. yes it isn't secure but its the customers fault in this case (unless something is terribly wrong with your cart)

    basically.. whenever customers click around.. they don't realize that there is an "ID" of some sort in the url (zencart uses zenID). If they are logged in, and have that zenID in the URL.. and copy paste that URL somewhere.. anyone who clicks that link will be logged into that customers account. It may not be so if the customer logged out and logged back in (assigned a different zenID) but im assuming they did not

  4. #4
    Join Date
    May 2005
    Posts
    110
    Plugin Contributions
    0

    Default Re: Customers details apparently on View

    I have just sent out a newsletter and the links i used within the newsletter include the zenid value from when i was logged in to the site and i copied the links. We have now had customers start clicking on links within the newsletter and start buying products under other peoples names and all sorts...

    Is there any way to fix this problem? These links could be clicked anytime over the next month and cause havok within our system.

    Your urgent help is much appreciated, thank you in advance!

    Brad.

  5. #5
    Join Date
    Jan 2004
    Posts
    66,419
    Blog Entries
    7
    Plugin Contributions
    277

    Default Re: Customers details apparently on View

    You don't have many options there.

    1. Don't do that

    2. Admin->Configuration->Sessions->Recreate Session ... set to True
    Hopefully your server configuration won't have a problem with this setting.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  6. #6
    Join Date
    May 2005
    Posts
    110
    Plugin Contributions
    0

    Default Re: Customers details apparently on View

    Here is a quick fix to the problem for anyone else you experiences it:

    using ftp download the
    includes/application_top.php
    search for zenid, rename it to session

    save and re-upload...


    make a backup first before ever making any changes

    Long term solution is to upgrade to the new version of zc :)

  7. #7
    Join Date
    Jan 2007
    Posts
    24
    Plugin Contributions
    0

    Default Re: Customers details apparently on View

    Did you end up solving this issue as I just had a customer experience the same issue.

    Thanks

  8. #8
    Join Date
    May 2005
    Posts
    110
    Plugin Contributions
    0

    Default Re: Customers details apparently on View

    See my post above.

 

 

Similar Threads

  1. Replies: 2
    Last Post: 5 Jul 2013, 10:58 PM
  2. Can't View Customer Details?
    By ardhill in forum General Questions
    Replies: 1
    Last Post: 23 Jul 2010, 09:26 AM
  3. Can't view order details since v1.3.9c
    By robbie269 in forum Upgrading from 1.3.x to 1.3.9
    Replies: 6
    Last Post: 24 May 2010, 10:21 PM
  4. Replies: 3
    Last Post: 10 Jul 2006, 11:47 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR