Zen Cart Logo
Forums / General Questions / Last things to check before launch?

Last things to check before launch?

Locked

Views: 1,730

Results 1 to 14 of 14
This thread is locked. New replies are disabled.
18 Oct 2007, 4:00 AM
#1
maperr55 avatar

maperr55

Zen Follower

Join Date:
Aug 2007
Location:
Manitou Beach, Michigan
Posts:
357
Plugin Contributions:
0

Last things to check before launch?

I am getting ready to launch my first store and have read through the security document and made the changes.
I search the posting and did not find an answer for these ones.

In the security Doc it suggests to move the cache folder but I'm not sure where they are suggesting where they want it move to so that it can not be browsed.

Besides the security doc steps are there any other things I need to do or be aware of to secure my site form attack?

Is there a way to mask the displayed URLs on the customers display so they can not be seen and used?

Any suggestions you may have would be grate or if there is someone you think I should get advice from please feel free to direct me in there direction.

22 Oct 2007, 8:34 PM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Last things to check before launch?

maperr55:

In the security Doc it suggests to move the cache folder but I'm not sure where they are suggesting where they want it move to so that it can not be browsed.This FAQ talks about relocating the "download" folder ... the concept is identical for the "cache" folder:
https://www.zen-cart.com/tutorials/index.php?article=280

maperr55:

Besides the security doc steps are there any other things I need to do or be aware of to secure my site form attack?
There is no absolute 100% definitive list. That's why we offer the Security Recommendations FAQ

maperr55:

Is there a way to mask the displayed URLs on the customers display so they can not be seen and used? What URLs?

23 Oct 2007, 12:36 AM
#3
maperr55 avatar

maperr55

Zen Follower

Join Date:
Aug 2007
Location:
Manitou Beach, Michigan
Posts:
357
Plugin Contributions:
0

Re: Last things to check before launch?

Thank you for your reply.
Perhapses the term URL ma be incorrect here so I'll describe it this way.
Using IE 6 browser at the bottom left corner of the screen in the gray bar you can see the address and doc paths as they load till Done shows. This is what I wondered, if it needed suppressing or hiding.
If I wanted to create a link into my store only from my web page link and wanted to hide it do I need to go that far?
Besides an Id and a password I'm not sure how an attacker would come after me and what he be looking for to gain an access portal. I know about password breaking programs but what are they looking for to get them to the point of being able to even enter an account password?
Now a days A person had to be careful you are trusting me with your information and take that very seriously. I want to do everything possible to protect that trust and your data when you buy from my on line store.
DR BYTE THANK YOU

23 Oct 2007, 3:30 AM
#4
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Last things to check before launch?

maperr55:

Perhapses the term URL ma be incorrect here so I'll describe it this way.
Using IE 6 browser at the bottom left corner of the screen in the gray bar you can see the address and doc paths as they load till Done shows. This is what I wondered, if it needed suppressing or hiding.Why would you think that needs hiding?
Is there something secret you're trying to protect?

maperr55:

If I wanted to create a link into my store only from my web page link and wanted to hide it do I need to go that far?Again, I must ask why you want to do this

maperr55:

Besides an Id and a password I'm not sure how an attacker would come after me and what he be looking for to gain an access portal. I know about password breaking programs but what are they looking for to get them to the point of being able to even enter an account password?Are you running on a server that has weak security? Is there a reason for being paranoid?

You could check out HackerSafe or an equivalent service that checks your site daily for common weaknesses if you think it's worth the expense.

I'd be more inclined to talk to your hosting company and ask them when the last time was that your server was hacked and what they did about it. Their response might give you a sense of how secure they run things and how much attention they pay to such issues.

If you feel the guidelines we've offered are insufficient, then you'll need to do your own research and become a self-educated expert on website security and ways to protect yourself from every possible angle of vulnerability. Perhaps you'll share your findings with the community when you're done, with an easy-to-read-and-implement how-to guide.

24 Oct 2007, 2:51 AM
#5
maperr55 avatar

maperr55

Zen Follower

Join Date:
Aug 2007
Location:
Manitou Beach, Michigan
Posts:
357
Plugin Contributions:
0

Re: Last things to check before launch?

I'm sorry if I'm giving you the wrong impression.
I just want to be certain to cover all bases for securing the site. I have such a hard time finding what I want to on the forum I wanted to be certain I hadn't missed any other security docs. If your saying that this doc closes most all attack routes thats good enough for me. Your experience on this software far exceeds mine, thus so many questions.
The idea with the easy to read server security guide sounds like a good idea.
This is something that I may be able to work up in time. All my background is with MS and Novell networks and its security which in most cases probably is simmilar awh but you know what happens when you assume. Not nothing I can learn just finished a couple years of MS server and networking classes and part of those were about securing networks that was about a year ago. If I am able to do this I would like your permission to contact you by e-mail instead of the forum with questions about ZC while composing this document. And then when completed submit it to you to review for accuracy. If thats OK with you. After that posting it would be fine with me.
You sound like you have been in the computer field for a very long time like myself. You know a very determined attacker will get through most sites security. So I just wanted to put as many hurtles in the way as possible.
You just hear so much about Identity theft these days I don't want to add to it or anyones problems.
My web host say there site is checked every day so I guess there secure enough.
As far as masking or hiding address I was just concerned that an attacker may be able to extract something from that information and use it to base or redirect from.
Being one of the victims of the Michigan economy instead of providing hardware/software support for a school district, I will need to learn the web software and server side to survive just more demand for it, my retirement and my ability too may depend on it.
I apologize again if I irked with my questions just wanted to be sure I had not missed anything. Thanks again, Mark

24 Oct 2007, 2:59 AM
#6
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Last things to check before launch?

No problem -- it's very important to pay attention to security.
If you do decide to write such a document, contact me via PM and reference this thread.

24 Oct 2007, 2:06 PM
#7
maperr55 avatar

maperr55

Zen Follower

Join Date:
Aug 2007
Location:
Manitou Beach, Michigan
Posts:
357
Plugin Contributions:
0

Re: Last things to check before launch?

Thanks again. This would be the least I could do since you have helped me so much.

Thanks Doc.
Mark

24 Oct 2007, 2:34 PM
#8
maperr55 avatar

maperr55

Zen Follower

Join Date:
Aug 2007
Location:
Manitou Beach, Michigan
Posts:
357
Plugin Contributions:
0

Re: Last things to check before launch?

In one of my stores I added a few htacess files where I thought they might be needed and now I'm getting 403 Forbidden errors when I try to use the Define Page Editor. I went back and renamed the added files but it did not correct the problem.
I browses the forum for the 403 error and tried the SecFilterEngine Off fix but that only produced a 500 server error.
Have I tripped a flag that needs to be reset?
Should I have one of these files for every folder that has an index.html file in it?
Before I try to apply this to any of the other stores I'd better find and fix this one. Damn I was just about to launch and open the store to, oh well just one more thing.

Let me update this by saying the I only get this message when I try to use FCKeditor; Plain text and htmlarea appear to work.

24 Oct 2007, 2:56 PM
#9
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Last things to check before launch?

You'll likely have to use your server's errorlog to find the cause of the 403-forbidden errors.

24 Oct 2007, 4:11 PM
#10
maperr55 avatar

maperr55

Zen Follower

Join Date:
Aug 2007
Location:
Manitou Beach, Michigan
Posts:
357
Plugin Contributions:
0

Re: Last things to check before launch?

Thanks I will check that.
How about the answer to this question. Should I have htaccess file for every folder that has an index.html file in it? If so in creating them should the entry be of the content of the security documents example file?

24 Oct 2007, 4:59 PM
#11
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
176

Re: Last things to check before launch?

If you want to put a .htaccess in every folder, feel free.
A more advanced study of .htaccess implementations often causes one to use its cascading features to deal with all folders under the folder where a given .htaccess exists.
If you're wanting to protect against directory listings specifically, a global setting to disallow index browsing would be far more efficient.

The existence of an index.html file will almost always prevent directory browsing because index.html is usually loaded as one of the default pages thus preventing access to the overall list of files in a given folder.

In short ... you can, but in most hosting configurations you won't need to. I can't speak for your specific situation because every webserver is configured differently.

24 Oct 2007, 5:42 PM
#12
maperr55 avatar

maperr55

Zen Follower

Join Date:
Aug 2007
Location:
Manitou Beach, Michigan
Posts:
357
Plugin Contributions:
0

Re: Last things to check before launch?

So as long as there is an htaccess file in a parent folder the child folder will also be protected by this files so there is really no need for it there correct?

Where would I find the place to change the setting if I wanted to disable global index browsing? Something my web host would need to set? What do I give up by doing this?

24 Oct 2007, 6:33 PM
#14
maperr55 avatar

maperr55

Zen Follower

Join Date:
Aug 2007
Location:
Manitou Beach, Michigan
Posts:
357
Plugin Contributions:
0

Re: Last things to check before launch?

Thank you I will read through them all.