Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
February 09, 2012, 04:16:28 PM

Pages: [1]   Go Down
  Print  
Author Topic: OSCommerce vulnerabilities  (Read 3596 times)
jimlongo
Intergalactic Superstar
*****
Offline Offline

Posts: 125



WWW
« on: January 13, 2010, 02:10:12 PM »

Having been hacked recently, I've discovered the doorway into my site was the OSCommerce application.

Please be aware that even the most current installation of OSCommerce is vulnerable to malicious intruders.  And the hacker community knows about these weaknesses. 

Please read the first post in the security forum at OSCommerce and follow the instructions contained there.

In short you should add some plug-ins to OSCommerce,  delete the file manager, password protect the admin directory and change its name. check all permissions of files and folders.

Good Luck.
Logged

Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #1 on: January 14, 2010, 05:52:41 AM »

Thanks for sharing Jim!
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
DEddleman
Spacescooter Operator
*****
Offline Offline

Posts: 34


Elite!


« Reply #2 on: January 14, 2010, 08:58:32 AM »

Also everyone here should take a moment to understand that any web application can be hacked. Even the latest versions have security holes (though they may not be discovered yet). The more widely-used an application is the bigger of a target it is. Vigilance is required and the best security practices should be followed.
Logged

Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #3 on: January 14, 2010, 09:03:36 AM »

Yes, very very true.  Thumbs Up
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
Pages: [1]   Go Up
  Print  
 
Jump to: