Forums / General Questions / SecurityMetrics are still finding vulnerabilities within PHP scripts on my server

SecurityMetrics are still finding vulnerabilities within PHP scripts on my server

Views: 1,784

Results 1 to 7 of 7
9 May 2011, 11:51 AM
#1
dunk avatar

dunk

Zen Follower

Join Date:
Dec 2007
Location:
London
Posts:
184
Plugin Contributions:
0

SecurityMetrics are still finding vulnerabilities within PHP scripts on my server

Had a quick search of the forums and was surprised I couldn't find too much detail relating to this.

We've been battling the issue of PCI compliance on and off for about 2 years (as covered here). Ultimately we're still not compliant.

I'm not sure how strongly enforced PCI compliance is in other territories but we're UK based and have been receiving monthly fines for non compliance for well over a year.
Our bank is now doubling the monthly non-compliance fine.
To try and resolve the problem we've migrated to a private server in recent weeks which has certainly helped but SecurityMetrics are still finding vulnerabilities within PHP scripts on the server, i.e. client side issues with Zen Cart.

I'm aware that the next big release of Zen Cart is supposed to address PCI compliance, but does anyone have any experience of making their current Zen Cart store compliant or perhaps can recommend someone we can ask for help?

We've reached the point where we're seriously considering switching to an entirely new ecommerce platform to achieve compliance. :frusty:

9 May 2011, 1:38 PM
#2
kobra avatar

kobra

Black Belt

Join Date:
Aug 2005
Location:
Arizona
Posts:
31,500
Plugin Contributions:
4

Re: SecurityMetrics are still finding vulnerabilities within PHP scripts on my server

Try completing the details as outlined in the posting FAQ's

http://www.zen-cart.com/forum/faq.php

Also what specific "vulnerabilities" are being referenced?
Are these due to php version?
If so, no script will be compliant

Zen-Venom Get Bitten

9 May 2011, 2:31 PM
#3
dunk avatar

dunk

Zen Follower

Join Date:
Dec 2007
Location:
London
Posts:
184
Plugin Contributions:
0

Re: SecurityMetrics are still finding vulnerabilities within PHP scripts on my server

No they're not due to PHP version.

Vulnerabilities highlighted are script issues.

Vulnerabilities such as
Script allows response splitting (Phorum)
Script allows response splitting (Surveys)
Script allows response splitting (W-Agora)
Script allows response splitting (webcalendar)
The remote web server contains a PHP script that is prone to an information disclosure attack.

We're running 1.3.9h, PHP 5.2.17, MySQL 5.0.92-community, hosted on a virtual private server

9 May 2011, 2:47 PM
#4
stevesh avatar

stevesh

Black Belt

Join Date:
Feb 2005
Location:
Lansing, Michigan USA
Posts:
19,793
Plugin Contributions:
2

Re: SecurityMetrics are still finding vulnerabilities within PHP scripts on my server

I'm no expert, but it looks to me that those issues have nothing to do with Zencart. Do you have those scripts installed ?

9 May 2011, 2:53 PM
#5
dunk avatar

dunk

Zen Follower

Join Date:
Dec 2007
Location:
London
Posts:
184
Plugin Contributions:
0

Re: SecurityMetrics are still finding vulnerabilities within PHP scripts on my server

Thanks for that, I think I know where to start looking.

I'm not familiar with the scripts but it's most likely that some of the custom mods that we've had developed are the root of the problem.

9 May 2011, 8:34 PM
#6
kobra avatar

kobra

Black Belt

Join Date:
Aug 2005
Location:
Arizona
Posts:
31,500
Plugin Contributions:
4

Re: SecurityMetrics are still finding vulnerabilities within PHP scripts on my server

Ditto stevesh

Those processes are not ZenCart processes TMK

Zen-Venom Get Bitten

12 May 2011, 11:11 AM
#7
ksl1 avatar

ksl1

New Zenner

Join Date:
Feb 2010
Posts:
28
Plugin Contributions:
0

Re: SecurityMetrics are still finding vulnerabilities within PHP scripts on my server

W-Agora is web publishing and forum script,
Phorum is PHP opensource. You are having compliance problems! None of those scripts are Zencarts