Zen Cart Logo
Forums / General Questions / Vulnerability Reports for Zen Cart.

Vulnerability Reports for Zen Cart.

Locked

Views: 2,382

Results 1 to 10 of 10
This thread is locked. New replies are disabled.
30 Oct 2006, 9:34 AM
#1
lokolobo avatar

lokolobo

New Zenner

Join Date:
Oct 2006
Location:
Minnesota
Posts:
10
Plugin Contributions:
0

Vulnerability Reports for Zen Cart.

30 Oct 2006, 11:47 AM
#2
paulm avatar

paulm

Totally Zenned

Join Date:
Nov 2003
Posts:
1,878
Plugin Contributions:
5

Re: Vulnerability Reports for Zen Cart.

As far as I can see all those reports are about 1.3.0.2 or older versions. So I assume/hope upgrading to 1.3.6 should fix these problems.

30 Oct 2006, 11:47 AM
#3
dogtags avatar

dogtags

Totally Zenned

Join Date:
Nov 2003
Posts:
876
Plugin Contributions:
1

Re: Vulnerability Reports for Zen Cart.

What does "Status Stable" mean ?

30 Oct 2006, 6:31 PM
#4
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Vulnerability Reports for Zen Cart.

paulm:

As far as I can see all those reports are about 1.3.0.2 or older versions. So I assume/hope upgrading to 1.3.6 should fix these problems.

PaulM is correct. The reported issues are all resolved and build-in to v1.3.5. Additional issues discovered by the Zen Cart team are included in v1.3.6.

It is recommended to upgrade to v1.3.6 to enjoy the security benefits, as well as the many other features and improvements contained therein.

30 Oct 2006, 6:33 PM
#5
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Vulnerability Reports for Zen Cart.

DogTags:

What does "Status Stable" mean ?

"Status Stable" just means they've stopped mucking with the details of their report and are satisfied that they can stop flogging it to say how bad it is or isn't. Basically it's an indicator to hackers about whether it's worth going after or whether they should wait until the vulnerability is deemed "stable" in order to go for the bigger payload.
Not exactly useful to anyone outside the "security vulnerability" industry.

31 Oct 2006, 12:19 PM
#6
dogtags avatar

dogtags

Totally Zenned

Join Date:
Nov 2003
Posts:
876
Plugin Contributions:
1

Re: Vulnerability Reports for Zen Cart.

Thanks, Dr. :-)

31 Oct 2006, 4:50 PM
#7
wickedklown avatar

wickedklown

Zen Follower

Join Date:
Aug 2005
Posts:
370
Plugin Contributions:
0

Re: Vulnerability Reports for Zen Cart.

DrByte:

"Status Stable" just means they've stopped mucking with the details of their report and are satisfied that they can stop flogging it to say how bad it is or isn't. Basically it's an indicator to hackers about whether it's worth going after or whether they should wait until the vulnerability is deemed "stable" in order to go for the bigger payload.
Not exactly useful to anyone outside the "security vulnerability" industry.

Sorry guys, i have to "VENT" on this one.....

its crap like that we dont need. Im sure that anyone of the zenners here that actualy make a living with this system are sad to hear that not only are there hackers out there waiting for the "prime time" to attack someone/company, but there is a place that shows them WHEN this time is good, and also go into details about the issue itself to point you directly to the place needed to "hack" the confidential data.
I already deal with fraudulant CC orders on a monthly basis!.(This is normal for my industry, and internet sales in general) I dont need the extra headache of wondering if someone is waiting to come take personal customer data which we hold so tight. Its horrable that is how our world works today...

Sure that site has its plus for the fact that it shows you this information, (im hoping for the benifit of being able to secure it down) but personaly i think its rediculas... Its like showing the world how the OK city bombing was created/exicuted in specific detail..... GRRRRRRRR!!!! Why not just ask someone to do it again?!?!?!?

Really the creators of this wonderfull system already know about issues and are always working hard to make sure they are rectified as quick as possable... So them -themselves dont really need this site to tell them where problems are... (this is why you donate to the team)....

Again, i dont mean to offend anyone with this post, im just in shock that we have sites like this around.... its just asking for trouble IMO......

1 Nov 2006, 8:21 AM
#8
lokolobo avatar

lokolobo

New Zenner

Join Date:
Oct 2006
Location:
Minnesota
Posts:
10
Plugin Contributions:
0

Re: Vulnerability Reports for Zen Cart.

I agree with you about being outraged with malicious hackers..
But the fact that that web site listed vulnerabilities is not nessasaraly a bad thing.. It helps with knowing the problem.. if you don't know what the problem is how do you know what needs to be fixed?

1 Nov 2006, 1:21 PM
#9
merlinpa1969 avatar

merlinpa1969

Totally Zenned

Join Date:
Mar 2004
Posts:
13,031
Plugin Contributions:
4

Re: Vulnerability Reports for Zen Cart.

I guess rather than post the issue and directions on exactly HOW to use the security exploit, it would be much better for these "security reporters" to QUIETLY let the developers of what ever software know.

that way it can be fixed before the script kiddies read about HOW to break in

1 Nov 2006, 3:55 PM
#10
wickedklown avatar

wickedklown

Zen Follower

Join Date:
Aug 2005
Posts:
370
Plugin Contributions:
0

Re: Vulnerability Reports for Zen Cart.

LokoLobo:

I agree with you about being outraged with malicious hackers..
But the fact that that web site listed vulnerabilities is not nessasaraly a bad thing.. It helps with knowing the problem.. if you don't know what the problem is how do you know what needs to be fixed?

GARRANTEED,
none of the creators of zencart need any site to inform them on what is wrong with the software... If they dont happen to find it themself, then rest assured- someone in the forums will bring it up....

i believe the Merlin is right... it should be a more private thing....