Sensei
- Join Date:
- Jan 2004
- Posts:
- 63,513
- Plugin Contributions:
- 176
Notice: Check Your Webserver Security Patches
While this post is not specifically about Zen Cart®, we felt it important to let you know about two common security problems that exist on multitudes of live webservers.
You should work with your hosting company to ensure these two problems are patched AS SOON AS POSSIBLE, lest your website could be hacked because of these server vulnerabilities:
-
PHP CGI Bug - http://arstechnica.com/security/2014/03/php-bug-allowing-site-hijacking-still-menaces-internet-22-months-on/ --- PHP versions 5.3.0-to-5.3.11 and 5.4.0-to-5.4.1 are vulnerable if they have CGI mode enabled.
-
SSL Flaw - http://heartbleed.com/ .... Inspect your own site via: http://possible.lv/tools/hb/
ALL QUESTIONS ABOUT THIS SUBJECT SHOULD BE DIRECTED TO YOUR HOSTING COMPANY
.
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.