Forums / Zen Cart Release Announcements / Notice: Check Your Webserver Security Patches

Notice: Check Your Webserver Security Patches

Locked

Views: 21,616

Results 1 to 2 of 2
This thread is locked. New replies are disabled.
8 Apr 2014, 8:06 PM
#1
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Notice: Check Your Webserver Security Patches

While this post is not specifically about Zen Cart®, we felt it important to let you know about two common security problems that exist on multitudes of live webservers.

You should work with your hosting company to ensure these two problems are patched AS SOON AS POSSIBLE, lest your website could be hacked because of these server vulnerabilities:

  1. PHP CGI Bug - http://arstechnica.com/security/2014/03/php-bug-allowing-site-hijacking-still-menaces-internet-22-months-on/ --- PHP versions 5.3.0-to-5.3.11 and 5.4.0-to-5.4.1 are vulnerable if they have CGI mode enabled.

  2. SSL Flaw - http://heartbleed.com/ .... Inspect your own site via: http://possible.lv/tools/hb/

ALL QUESTIONS ABOUT THIS SUBJECT SHOULD BE DIRECTED TO YOUR HOSTING COMPANY

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

9 Apr 2014, 6:09 PM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Notice: Check Your Webserver Security Patches

Pardon the additional email this update may trigger ...

RE: ZEN-CART.COM SERVERS
In case you were wondering (some have asked privately), we at Zen Cart have inspected our systems to verify that our servers were not open to these vulnerabilities.

Further, we remind you that we specifically do not store any sensitive financial information on any of our servers.

UPDATE TO PREVIOUS POST:
Also, I've updated the post above to add clarification about which specific PHP versions were affected by the CGI vulnerability: PHP versions 5.3.0-to-5.3.11 and 5.4.0-to-5.4.1 are vulnerable, if CGI mode is enabled.

.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole

Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.