Oscommerce Security - Osc_Sec.php
#421
Posted 11 January 2012, 00:07
I uncommented the code, changed the $banipaddress and clicked on the Edit button and got the same error message.
However, when I check the htaccess file, my IP address has not been added to the file, and I didn't receive any email notification.
Thanks
Simon
#422
Posted 11 January 2012, 02:21
- Another discussion about infected files ::here::
- A discussion on file permissions ::here::
- Site hacked? Should you upgrade or not, some thoughts ::here::
- Ignore this link - just a honeypot site to test my ideas out for osC_Sec and allow the site to be picked up by attackers.
- Fix the admin login bypass exploit here
#423
Posted 13 January 2012, 18:33
#424
Posted 13 January 2012, 19:01
One of the accounts is called admincrash.
I have installed this now. Changed all passwords. what is the next thing to do now?
Edited by nudylady, 13 January 2012, 19:09.
#425
Posted 13 January 2012, 22:48
Some basic steps on how to do this can be found in my profile.
Also links to some other actions you need to do such as renameing admin dir and ....
HTH
G
Edited by geoffreywalton, 13 January 2012, 22:50.
Virus Threat Scanner
My Contributions
Basic install answers.
Click here for Contributions / Add Ons.
UK your site.
Site Move.
Basic design info.
For links mentioned in old answers that are no longer here follow this link Useful Threads.
If this post was useful, click the Like This button over there ======>>>>>.
#426
Posted 10 February 2012, 08:48
I often receive this message - even though its clearly not a hacker attempt: "osC_Sec detected malicious cookie content..."
And since I use IP trap, the IP is banned.
Thanks!
#427
Posted 10 February 2012, 08:58
$this->cookieShield();
and replace with:
# $this->cookieShield();
- Another discussion about infected files ::here::
- A discussion on file permissions ::here::
- Site hacked? Should you upgrade or not, some thoughts ::here::
- Ignore this link - just a honeypot site to test my ideas out for osC_Sec and allow the site to be picked up by attackers.
- Fix the admin login bypass exploit here
#428
Posted 15 February 2012, 22:14
Installation produces a 500 (if I recall correctly) error (note, osc_sec files only, not using the htaccess modifications).
Support is commercially available. The question is whether you value your business
highly enough to spend money on it.
For commercial support from known developers who support osCommerce
ethos, please post at http://forums.oscommerce.com/forum/79-commercial-support/
#429
Posted 16 February 2012, 04:02
http://pastebin.com/Hn2ifX6U
( grab the code from the raw paste data at the bottom )
Let me know if that sorts the issue, if so I will post an update.
Edited by Taipo, 16 February 2012, 04:02.
- Another discussion about infected files ::here::
- A discussion on file permissions ::here::
- Site hacked? Should you upgrade or not, some thoughts ::here::
- Ignore this link - just a honeypot site to test my ideas out for osC_Sec and allow the site to be picked up by attackers.
- Fix the admin login bypass exploit here
#430
Posted 16 February 2012, 12:02
Support is commercially available. The question is whether you value your business
highly enough to spend money on it.
For commercial support from known developers who support osCommerce
ethos, please post at http://forums.oscommerce.com/forum/79-commercial-support/
#431
Posted 21 February 2012, 03:38
#432
Posted 21 February 2012, 03:52
In fact you do not need to edit anything if you just want to add it, however if you want to ban ip addresses and such then osc.php is the file you want to look in. Check the readme.htm file for more on editing the settings.
- Another discussion about infected files ::here::
- A discussion on file permissions ::here::
- Site hacked? Should you upgrade or not, some thoughts ::here::
- Ignore this link - just a honeypot site to test my ideas out for osC_Sec and allow the site to be picked up by attackers.
- Fix the admin login bypass exploit here
#433
Posted 21 February 2012, 09:42
Whats New?
- Added extra checks in $checkfilename
- Fixed an issue where files contain extra '.'. i.e. file.name.php
- Fix phpSelfFix() function
- Fixed whitespace issue with $this->_httphost
- More additions to the dbShield() function to protect against database injection attempts
- Fixed a number of issues with dbShield() to prevent false positives
- Removed base64_decode aspect of dbShield() due to it causing errors in some configurations
- More additions to getShield() function to detect local file read attempts
- Remake of the postShield() function
- Remake of the cookieShield() function
- Fixed an error in ipTrapped()
New Install instructions: see the readme.htm, as per usual, all updates contain the complete package
Updating:
Replace the osc_sec.php file in your catalogs /includes/ directory with the one in the /includes/ directory of this zip file.
Please report any bugs to the discussion forums at http://goo.gl/dQ3jH or email rohepotae@gmail.com
Download from: http://addons.oscommerce.com/info/8283
- Another discussion about infected files ::here::
- A discussion on file permissions ::here::
- Site hacked? Should you upgrade or not, some thoughts ::here::
- Ignore this link - just a honeypot site to test my ideas out for osC_Sec and allow the site to be picked up by attackers.
- Fix the admin login bypass exploit here
#434
Posted 27 February 2012, 16:58
Google & Babel translate do not work on my site anymore, could the OSC SEC contirbution be stopping it from working?
I also have Security Pro 2.0 installed.
These are the characters Google uses
http://translate.google.com/translate?hl=en&sl=en&tl=sq&u=http%3A%2F%2Fwww.oscommerce.com%2F
And this is what Babel uses
http://babelfish.yahoo.com/translate_url?doit=done&tt=url&intl=1&fr=bf-home&trurl=http%3A%2F%2Fwww.oscommerce.com%2F&lp=en_nl&btnTrUrl=Translate
I added % and & and = to the Secuity Pro whitelist but the translation from these pages comes back as
blank page for Google and with an
error(0) for Babel
Edited by RMD27, 27 February 2012, 16:59.
#435
Posted 27 February 2012, 18:02
Warning: file () [ function.file ]: Emri nuk mund të jetë bosh në / home / mydomain / public_html / përfshinë / osc_sec.php on line 675
Edited by ptt81, 27 February 2012, 18:02.
#436
Posted 27 February 2012, 18:20
- Another discussion about infected files ::here::
- A discussion on file permissions ::here::
- Site hacked? Should you upgrade or not, some thoughts ::here::
- Ignore this link - just a honeypot site to test my ideas out for osC_Sec and allow the site to be picked up by attackers.
- Fix the admin login bypass exploit here
#437
Posted 27 February 2012, 18:57
Warning : file() [ function.file ]: Filename cannot be empty in /home/mydomain/public_html/includes/osc_sec.php on line 675
Warning : Cannot modify header information - headers already sent by (output started at /home/mydomain/public_html/includes/osc_sec.php:675) in /home/mydomain/public_html/includes/functions/general.php on line 1355
Edited by ptt81, 27 February 2012, 19:00.
#438
Posted 29 February 2012, 13:19
#439
Posted 01 March 2012, 10:39
- Another discussion about infected files ::here::
- A discussion on file permissions ::here::
- Site hacked? Should you upgrade or not, some thoughts ::here::
- Ignore this link - just a honeypot site to test my ideas out for osC_Sec and allow the site to be picked up by attackers.
- Fix the admin login bypass exploit here
#440
Posted 01 March 2012, 13:27
Unfortunately no difference. Maybe it is something to do with FWRs plug in. Ill leave a message on his support thread and let you know what he says!
http://forums.oscommerce.com/topic/293326-contribution-security-pro-querystring-protection-against-hackers/page__hl__fwr__st__240














