Zen Cart Logo
Forums / All Other Contributions/Addons / OLD Super Orders 2.0 (See v3.0 thread instead)

OLD Super Orders 2.0 (See v3.0 thread instead)

Locked

Views: 456,074

Results 1,361 to 1,380 of 2,020
This thread is locked. New replies are disabled.
7 Aug 2009, 1:44 AM
#1361
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

OLD Super Orders 2.0 (See v3.0 thread instead)

In all likelihood they have been hacked and then the script kiddie has run riot since their admin folder is in the default place. Going to the admin folder results in problems with SEO too in the auto_load functions so I am guessing that it's a hack and then break the server to stop anyone else. A quick scan before my ip got blocked (that was ME not a bad guy) showed an odd port open on 2222 which is listed as a rootkit shell port but then it could just be SSH bein forwarded to a non obvious port.

http://www.google.co.uk/search?hl=en&q=port+2222+rootkit

lists quite a few rootkits there. I think they need professional help, and probably shouldn't be posting here either, more int he security section.

Philip.

7 Aug 2009, 2:12 PM
#1362
dw08gm avatar

dw08gm

Totally Zenned

Join Date:
Sep 2008
Location:
DownUnder, overlooking South Pole.
Posts:
1,017
Plugin Contributions:
2

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

philip_clarke:

In all likelihood they have been hacked and then the script kiddie has run riot since their admin folder is in the default place. Going to the admin folder results in problems with SEO too in the auto_load functions so I am guessing that it's a hack and then break the server to stop anyone else. A quick scan before my ip got blocked (that was ME not a bad guy) showed an odd port open on 2222 which is listed as a rootkit shell port but then it could just be SSH bein forwarded to a non obvious port.

http://www.google.co.uk/search?hl=en&q=port+2222+rootkit

lists quite a few rootkits there. I think they need professional help, and probably shouldn't be posting here either, more int he security section.

Philip.

Philip, you absolutely amaze me with the things you uncover. I love it.

What was the scan you did that showed the open port 2222?

7 Aug 2009, 3:07 PM
#1363
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

Standard nmap scan, there seems to be some snort-like feature enabled on that server or a router further down the chain, as after the scan it then ceased communication with the ip address it was scanned from (not my web browser address) so I investigated further and found that the site is/ was a 1.3.7 as listed conveniently here:

http://www.maternitystar.com.au/docs/

a little more investigation now that the block has cleared show that port 2222 is a forwarded SSH port that you can try and log in on. It's also a Red Hat Enterprise Linux Server because helpfully it says so in the browser headers (you can read them in firefox)

HTTP/1.1 200 OK
Date: Fri, 07 Aug 2009 14:57:32 GMT
Server: Apache/2.2.11 (Unix) mod_ssl/2.2.11 OpenSSL/0.9.8e-fips-rhel5 mod_bwlimited/1.4 mod_perl/2.0.4 Perl/v5.8.8

Please note that at no point have I attempted to gain access to this machine or it's data. I am just giving a considered opinion that the server has been wrecked, in all likelihood by a script kiddie covering his/ her tracks by doing rm *.php after they've done their business. I saw this a lot about 3/ 4 weeks ago when a proof of concept exploit was published. Also it appears that modifications to morfeus and santy have already been done since requests for zen cart shops are now appearing much higher up the rank in some honey traps I have laid out.

With any luck that site could be restores quite easily depending on the damage the kiddie has done naturally. I'd start by sweeping for backdoors though. The wrecking was probably to cover tracks, professional hackers tend to go quietly in and leave things untouched to the outside eye, (hence the port scan to see if there was any indication of an IRC controlled bot). The more skilled professional hacker tends to be of the opinion that there is no point in hacking a server to reap credit cards, join a bot net, send out spam, store illegal files etc... if the website's owner is going to take down the website because it's been trashed.

I reckon one of two causes. a) big hard drive failure leading to large sections of the drive being unreadable (but not "that" likely as the main directory structure of the site looks intact.
b) script kiddie

Naturally I have only looked from the outside bit like shining a torch on a car wreck, as going in would be covered by the "computer misuse act" in the UK and I haven't been invited.

Philip.

9 Aug 2009, 5:29 PM
#1364
dw08gm avatar

dw08gm

Totally Zenned

Join Date:
Sep 2008
Location:
DownUnder, overlooking South Pole.
Posts:
1,017
Plugin Contributions:
2

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

It is always good to know your enemy. I did the search as per your previous post and started reading the madirish blog (IIRC) and a few others. Amazing stuff. While I don't ever expect to catch up, I can only hope my site is interesting enough not to be hacked. Otherwise I will erect a sign saying "This site is protected by extreme poverty". Thanks for the heads up.

9 Aug 2009, 6:07 PM
#1365
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

http://news.bbc.co.uk/1/hi/world/europe/country_profiles/8123450.stm

is an interesting article about "quiet" hackers as I call them, note that they aim was not money when they took over the website, also the Swiss police did not arrest the website owner which is unusual.

10 Aug 2009, 10:22 AM
#1366
rpain avatar

rpain

Zen Follower

Join Date:
Mar 2005
Location:
Watford, UK
Posts:
146
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

OK - question related to the mod. I have got a set of customers (about 200) who have bought some particular item. I'd like to send an email to just those customers - is this possible within the interface (or with a simple mod) or do I need to start fiddling around generating huge sql queries and extracting emails that way? I'm using the latest version.

Thanks,
Richard

10 Aug 2009, 11:14 AM
#1367
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

Zen Cart has the newsletter feature built in, not this, that kind of email would also fall foul of the USA spam (and probably our) rules if they were given the chance to opt into a newletter and you just went an ignored it even if it were limited to one item, and apart from that it's fiddling time.

Philip.

10 Aug 2009, 4:02 PM
#1368
carlvt88 avatar

carlvt88

Zen Follower

Join Date:
Aug 2007
Location:
Williston, Vermont
Posts:
180
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

Check out the query factory. This uses the zencart newsletter feature and allows you to build in a custom list for distribution. So, you can specify a query that will select the users who bought that particular item.

10 Aug 2009, 4:56 PM
#1369
carlvt88 avatar

carlvt88

Zen Follower

Join Date:
Aug 2007
Location:
Williston, Vermont
Posts:
180
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

a.k.a. query builder. I don't know if there's a good interface into it, but I've used the query_builder table in the database, added a query, and used it for custom newsletter addressing.

2 Sep 2009, 10:19 AM
#1370
andy_gs avatar

andy_gs

Zen Follower

Join Date:
Jun 2008
Posts:
187
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

Hello, right i've tried to do an upgrade of an older version of super orders. I followed the instructions to install super orders then did the instructions of the upgrade.txt

When i ran the sql patch i got this error:

1062 Duplicate entry 'CA' for key 2
in:
[INSERT INTO so_payment_types VALUES (NULL, 1, 'CA', 'Cash');]
If you were entering information, press the BACK button in your browser and re-check the information you had entered to be sure you left no blank fields.

Then when i went to run the upgrade.php

1146 Table 'db_name.payment_purchase_order' doesn't exist
in:
[select * from payment_purchase_order]
If you were entering information, press the BACK button in your browser and re-check the information you had entered to be sure you left no blank fields.

We only use super orders to do the follow:

  • batch processing
  • and to ammend shipping addresses once orders have been placed.

as far as i can tell the site is still working.

The reason we needed to upgrade was when clicking on the buttons within super orders it would cause tables to lock up. The way round this was not to click directly on the buttons but to click somewhere within the block element, however people in this office can't always remeber to do that so they asked me to fix it.

Any ideas?

regards

Andy.

6 Sep 2009, 2:59 PM
#1371
remoteone avatar

remoteone

Zen Follower

Join Date:
Jan 2009
Location:
Macclesfield, South Australia
Posts:
104
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

Yes, i just did a new install (on localhost test machine) and got a similar error when running the sql.

SQL query:
-- EDIT EXISTING TABLES
ALTER TABLE orders ADD date_completed datetime default NULL ;
MySQL said: Documentation
**#1146 - Table 'db_name.orders' doesn't exist **

("db_name" is not my real dB prefix)
What does it all mean?
Cheers

6 Sep 2009, 5:29 PM
#1372
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

remoteone:

Yes, i just did a new install (on localhost test machine) and got a similar error when running the sql.

("db_name" is not my real dB prefix)
What does it all mean?
Cheers

id you install the patch using your shop admin ? because in all likelihood the table is called zen_orders and won't run through a mysql console.

Philip.

6 Sep 2009, 8:30 PM
#1373
divavocals avatar

divavocals

Totally Zenned

Join Date:
Jan 2007
Location:
Los Angeles, California, United States
Posts:
10,011
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

philip_clarke:

id you install the patch using your shop admin ? because in all likelihood the table is called zen_orders and won't run through a mysql console.

Philip.To add on: hence why you got the error that the table doesn't exist. (db_name.orders should be db_name.zen_orders)

So you can either manually edit the SQL to correct the table names (not advised) OR take Phillips excellent advice and run the script using the Zen Cart admin SQL update tool (the admin tool makes the correction for you as it runs the SQL script)

6 Sep 2009, 11:37 PM
#1374
remoteone avatar

remoteone

Zen Follower

Join Date:
Jan 2009
Location:
Macclesfield, South Australia
Posts:
104
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

Hello,
Thanks for advice and fast reply. By "Zen Cart admin SQL update tool " you mean "SQL Query Executor" under "install SQL patches".
Looking at the INSTRUCTIONS, I see it clearly states to:

  1. Run the super_orders_sql.sql file on your database. Will work with
    the "SQL Query Executor" tool in the Admin (Tools > Install SQL Patches).
    For those the likes of myself, perhaps it should say:
  2. Upload the super_orders_sql.sql file on your database. Will ONLY reliably work with
    the "SQL Query Executor" tool in the Admin (Tools > Install SQL Patches) by UPLOADing the .sql file.
    Since most Mod's Ive installed seem to prefer the cut-n-paste code method, I default to using it to install SQL script by cut-n-paste the code using phpMyAdmin. Assuming the Mod's script has been written to be compatible, and not need correction.

So Upload the .sql file (as instructed) I now get this error:

1062 Duplicate entry 'CA' for key 2
in:
[INSERT INTO db_name_so_payment_types VALUES (NULL, 1, 'CA', 'Cash');]
If you were entering information, ..blah blah blah....
Which I hope is ok. I guess it just means that the table already exists from my previous attempts.
So it should work now ???
cheers

6 Sep 2009, 11:39 PM
#1375
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

yes. (this message needs 7 characters)

6 Sep 2009, 11:55 PM
#1376
remoteone avatar

remoteone

Zen Follower

Join Date:
Jan 2009
Location:
Macclesfield, South Australia
Posts:
104
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

Ok that was step 3.
Step 4. ...theres no "Store Phone" or "Store Fax" showing under [Config> My Store]. (Apache restarted and Cache cleared)
Maybe I need to restore my previous SQL table and start again.

6 Sep 2009, 11:57 PM
#1377
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

remoteone:

Ok that was step 3.
Step 4. ...theres no "Store Phone" or "Store Fax" showing under [Config> My Store]. (Apache restarted and Cache cleared)
Maybe I need to restore my previous SQL table and start again.

It would be better to remove the lines that give you problems in the Install SQL patches. The sequence of sql is probably falling over at the first error.

7 Sep 2009, 12:40 AM
#1378
remoteone avatar

remoteone

Zen Follower

Join Date:
Jan 2009
Location:
Macclesfield, South Australia
Posts:
104
Plugin Contributions:
0

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

I restored previous sql database and Uploaded the super_orders_sql.sql file. Got this error:

1366 Incorrect integer value: '' for column 'configuration_id' at row 1
in:
[INSERT INTO mydBprefix_configuration VALUES ('', 'Store Fax', 'STORE_FAX', '', 'Enter the fax number for your store.
You can call upon this by using the define STORE_FAX.', 1, 4, now(), now(), NULL, NULL);]
If you were entering information, etc etc...
Still no "Store Phone" or "Store Fax".

It would be better to remove the lines that give you problems in the Install SQL patches. The sequence of sql is probably falling over at the first error.
Thanks Philip,
Well I'm not sure where to start with that, but I do want to be able to define "Store Phone" separately to the Store Address.
As it stands there is currently no STORE_FAX nor STORE_PHONE [configuration_key] after uploading the .sql.
Cheers

7 Sep 2009, 12:49 AM
#1379
philip_clarke avatar

philip_clarke

Suspended

Join Date:
Sep 2008
Posts:
608
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

remoteone:

I restored previous sql database and Uploaded the super_orders_sql.sql file. Got this error:

Still no "Store Phone" or "Store Fax".

Thanks Philip,
Well I'm not sure where to start with that, but I do want to be able to define "Store Phone" separately to the Store Address.
As it stands there is currently no STORE_FAX nor STORE_PHONE [configuration_key] after uploading the .sql.
Cheers

If you put the mouse over the menu that drops down when you are admin configuration, you'll see all these group_ids and configuration ids. These are how ZC would file the store_name, phone configuration bits. Somehow yours have gone wonky. The SQL should be able to bite into the correct menu from doing a lookup in your database, it should fill in the numbers (those missing integer values) and it should the execute the SQL. Would could run the sql manually through phpMyAdmin if your could get the correct numbers. Can't tell you what the numbers are, because with each installation of modules they change around a bit. I think yours are certainly well into the "changed" bit, so I couldn't guess.

Philip.

7 Sep 2009, 1:14 AM
#1380
divavocals avatar

divavocals

Totally Zenned

Join Date:
Jan 2007
Location:
Los Angeles, California, United States
Posts:
10,011
Plugin Contributions:
3

Re: OLD Super Orders 2.0 (See v3.0 thread instead)

remoteone:

Since most Mod's Ive installed seem to prefer the cut-n-paste code method, I default to using it to install SQL script by cut-n-paste the code using phpMyAdmin. Assuming the Mod's script has been written to be compatible, and not need correction.And you will likely have the same kinds of problems with other mods doing this.. If you haven't consider yourself lucky.. Most of the SQL written for these mods would have NO IDEA what table prefix you've used when you created your database (you do NOT have to use "zen_"). From my understanding, the "Install SQL Patches" tool would make sure that the correct table prefix is used so that these SQL patches so that the correct tables are created or amended. If you are proficient with SQL, you could edit the SQL statements yourself and continue to use your phpMyAdmin..