How to secure your osCommerce 2.2 site.
#101
Posted 23 March 2009, 13:12
ie SecurityPro_installer.php in your browser!!!!!!!!!
Remember, What you think I ment may not be what I thought I ment when I said it.
Contributions:
Auto Backup your Database, Easy way
Multi Images with Fancy Pop-ups, Easy way
Products in columns with multi buy etc etc
Disable any Category or Product, Easy way
Secure & Improve your account pages et al.
#102
Posted 23 March 2009, 22:16
Thanks for taking the timeto help me.
Anthony
spooks, on Mar 23 2009, 01:12 PM, said:
ie SecurityPro_installer.php in your browser!!!!!!!!!
#103
Posted 24 March 2009, 02:36
Coopco, on Mar 23 2009, 08:55 AM, said:
I do not have your htaccess stuff (a lot of this stuff did not work for me anyway and crashed my site).
I do have ip trap working.
My only issue is with Security Pro and the files that I added to Security Pro exclude list in admin.
Security Pro on, modules do not work.
Security Pro off, modules do work.
Security Pro is now off before I permantently remove it.
I thougth I had that situation too... but curiously enough having tried everything else... I decided to put Security Pro back up (cause I remembered that I installed that one first, Site Monitor second and IP Trap last... and after installing Security Pro... everything was working with my payments)... so Security Pro is back on... I removed the call to the secret.php file in the application_top.php file and funny enough... my payments are working again. As soon as my site isn't interacting with the Ip Trap contrib... all is well. As soon as I put the call to secret.php file, everything starts to go wrong again.
I'm starting to think that maybe what I did wrong is how I coded this line that shows up twice in personal/index.php and once in includes/secret.php : /home/***username***/public_html/catalog/banned/IP_Trapped.txt
I coded mine this way... and please note, I'm sooooooooooo not an expert so I'm pretty sure I did it wrong:
/var/www/vhosts/mysite.com/httpdocs/catalog/banned/IP_Trapped.txt
could it be that I did that wrong and it's what's been creating all this havoc?
Any toughts?
#104
Posted 24 March 2009, 07:02
mariemeh, on Mar 24 2009, 01:36 PM, said:
I'm starting to think that maybe what I did wrong is how I coded this line that shows up twice in personal/index.php and once in includes/secret.php : /home/***username***/public_html/catalog/banned/IP_Trapped.txt
I coded mine this way... and please note, I'm sooooooooooo not an expert so I'm pretty sure I did it wrong:
/var/www/vhosts/mysite.com/httpdocs/catalog/banned/IP_Trapped.txt
could it be that I did that wrong and it's what's been creating all this havoc?
Any toughts?
The Coopco Underwear Shop
If you live to be 100 years of age, that means you have lived for 36,525 days. Don't waste another, there aren't many left.
#105
Posted 24 March 2009, 15:03
Every single time I remove the call to the secret.php page in the application_top.php page... everything works. The htaccess file new code doesnt' seem to affect anything... the new robot.txt file doesn't affect anything either in the working of my site nor is Security Pro or Site Monitor...and I would think the robot.txt and htaccess files, if they were causing issues, would still be causing them weither the call to the IP Trap contrib was made or not. I'm not a pro at this... but that's what my gut's telling me at this time.
If anything in my thinking is flawed... don't hesitated to say so.
#106
Posted 25 March 2009, 08:10
mariemeh, on Mar 25 2009, 02:03 AM, said:
Every single time I remove the call to the secret.php page in the application_top.php page... everything works. The htaccess file new code doesnt' seem to affect anything... the new robot.txt file doesn't affect anything either in the working of my site nor is Security Pro or Site Monitor...and I would think the robot.txt and htaccess files, if they were causing issues, would still be causing them weither the call to the IP Trap contrib was made or not. I'm not a pro at this... but that's what my gut's telling me at this time.
If anything in my thinking is flawed... don't hesitated to say so.
The Coopco Underwear Shop
If you live to be 100 years of age, that means you have lived for 36,525 days. Don't waste another, there aren't many left.
#107
Posted 02 April 2009, 12:45
Any step by step support without being flamed would be greatly appreciated
re instruction
Firstly: -
"Upload SecurityPro_installer.php to your catalog folder. Browse to it and the installation will auto insert your admin settings."
When I try to open the php script in IE it just shows a page of text and doesn't appear run the script. How can I tell if it updated?
I am okay with the other instructions until I get to
"Go into admin>configuration>FWR Security Pro and turn it on .. (set to true)."
Is this through my store (catalog/admin control panel - same place as new administrators are set up?) or should it be available thro' FTP? I can't see it in either but that may be down to me getting step 1 wrong!!!
#108
Posted 02 April 2009, 12:52
scfcrob, on Apr 2 2009, 10:45 PM, said:
Any step by step support without being flamed would be greatly appreciated
re instruction
Firstly: -
"Upload SecurityPro_installer.php to your catalog folder. Browse to it and the installation will auto insert your admin settings."
When I try to open the php script in IE it just shows a page of text and doesn't appear run the script. How can I tell if it updated?
I am okay with the other instructions until I get to
"Go into admin>configuration>FWR Security Pro and turn it on .. (set to true)."
Is this through my store (catalog/admin control panel - same place as new administrators are set up?) or should it be available thro' FTP? I can't see it in either but that may be down to me getting step 1 wrong!!!
If that does not work, then you cannot do anything in your admin.
The Coopco Underwear Shop
If you live to be 100 years of age, that means you have lived for 36,525 days. Don't waste another, there aren't many left.
#109
Posted 18 April 2009, 01:59
Thank you in advance for your time and consideration.
#110
Posted 18 April 2009, 07:51
these contribs work on the client side, so anything operating on the admin side is un-affected.
Remember, What you think I ment may not be what I thought I ment when I said it.
Contributions:
Auto Backup your Database, Easy way
Multi Images with Fancy Pop-ups, Easy way
Products in columns with multi buy etc etc
Disable any Category or Product, Easy way
Secure & Improve your account pages et al.
#111
Posted 18 April 2009, 09:23
#112
Posted 22 April 2009, 06:43
#113
Posted 23 April 2009, 23:55
Remember, What you think I ment may not be what I thought I ment when I said it.
Contributions:
Auto Backup your Database, Easy way
Multi Images with Fancy Pop-ups, Easy way
Products in columns with multi buy etc etc
Disable any Category or Product, Easy way
Secure & Improve your account pages et al.
#114
Posted 24 April 2009, 02:45
Tomorrow he'll add " thanks a lot".
Ha HA ha
Note: I just kidding (no offense)... some pick of fun is always necessary
#115
Posted 04 May 2009, 06:53
edit, this is the add-on I'm referring to.
http://addons.oscommerce.com/info/5752
edit, I have found I can exclude the tell_a_friend.php from the cleansing via the admin, but this isn't really ideal I don't think since I would be leaving a gap in the overall security of the site, maybe I'm wrong on that.
Edited by Eirik, 04 May 2009, 07:01.
#116
Posted 04 May 2009, 08:24
<?php echo '<a href="' . tep_href_link(FILENAME_TELL_A_FRIEND, 'products_id=' . $HTTP_GET_VARS['products_id']) . '">' . tep_image_button('button_tell_a_friend.gif', BOX_HEADING_TELL_A_FRIEND) . '</a>'; ?>
That link can be placed anywhere within the product page and will send the product information to the tell_a_friend.php
#117
Posted 05 May 2009, 20:04
in security.php
return preg_replace("/[^ {}a-zA-Z0-9_.-]/i", "", urldecode($get_var));
to allow the @ put
return preg_replace("/[^ {}a-zA-Z0-9@_.-]/i", "", urldecode($get_var));
Edited by spooks, 05 May 2009, 20:06.
Remember, What you think I ment may not be what I thought I ment when I said it.
Contributions:
Auto Backup your Database, Easy way
Multi Images with Fancy Pop-ups, Easy way
Products in columns with multi buy etc etc
Disable any Category or Product, Easy way
Secure & Improve your account pages et al.
#118
Posted 05 May 2009, 20:08
spooks, on May 5 2009, 08:04 PM, said:
in security.php
return preg_replace("/[^ {}a-zA-Z0-9_.-]/i", "", urldecode($get_var));
to allow the @ put
return preg_replace("/[^ {}a-zA-Z0-9@_.-]/i", "", urldecode($get_var));
Thanks so much, you are a gentleman and a scholar sir!
#119
Posted 07 May 2009, 18:48
EricK, on Dec 30 2008, 01:19 AM, said:
Files changed:
catalog/includes/secret.php
catalog/personal/index.php
Regards,
Eric_K
i am having the same problem with the 99.999.99.999 and i still am not baned. i changed the single quotes to double and that didn fix it.
help?!?
will
#120
Posted 07 May 2009, 18:53
Also, I just rec'd about 7 emails that my ip has been banned however I can still do whatever I want at my site.
When I opened IP_Trapped.txt my ip is not listed, it shows 999.999.999.999
I got the IP Trap to work by replacing the " " double quotes with ' ' single quotes where you define absolute path to '/home/***username***/public_html/catalog/banned/IP_Trapped.txt'
Files changed:
catalog/includes/secret.php
catalog/personal/index.php
Regards,
Eric_K
i am having a probem with ip trap it just shows the 999.999.999.999 and i am not baned even thou i tryed to ban myself i did the above fix but it didnt fix the problem. i still am not baned.
please help me
will














