Community Forums

Possible OpenCart Security Issue

News, updates and important issues relating to OpenCart.

Re: Possible OpenCart Security Issue

Postby Xsecrets » Thu Sep 08, 2011 1:18 pm

wolfsteritory wrote:
JAY6390 wrote:There's no reason you can't update the cache file, but it should be the data input that's sanitized IMO



what exactly do you mean by that ?

thank you

he means that the data should be sanitized as soon as you assign it to a variable in the zone file not after you've passed it off to two other files and gotten to the chache file.
Xsecrets
 
Posts: 5042
Joined: Sat Oct 24, 2009 7:51 pm
Location: FL US

Re: Possible OpenCart Security Issue

Postby webpie it. » Thu Sep 08, 2011 5:43 pm

So from reading this over time is it confirmed that the cache file should be updated?

Thanks

Chris
Regards

Chris
webpie it.
 
Posts: 374
Joined: Mon Jan 31, 2011 11:28 am

Re: Possible OpenCart Security Issue

Postby Xsecrets » Thu Sep 08, 2011 6:25 pm

webpie it. wrote:So from reading this over time is it confirmed that the cache file should be updated?

Thanks

Chris

well yes currently it is the only solution to the problem that has been provided. Though it really should not have to be changed, because you should never pass data to it that has not been sanitized, but at this point yes I would implement the fix if you have a live store.
Xsecrets
 
Posts: 5042
Joined: Sat Oct 24, 2009 7:51 pm
Location: FL US

Re: Possible OpenCart Security Issue

Postby Qphoria » Thu Sep 08, 2011 6:35 pm

webpie it. wrote:So from reading this over time is it confirmed that the cache file should be updated?

Thanks

Chris


Yes
Image Image
Donate!|OpenCart Basics|GeoZones
Help me get more development cloud storage - Click Here to get DropBox
User avatar
Qphoria
Administrator
 
Posts: 18200
Joined: Mon Jul 21, 2008 7:02 pm
Donate to Qphoria

Re: Possible OpenCart Security Issue

Postby fealldagal » Thu Sep 08, 2011 6:58 pm

Can someone help me i have 3 stores thank you
fealldagal
 
Posts: 8
Joined: Thu Oct 29, 2009 5:31 pm

Re: Possible OpenCart Security Issue

Postby fealldagal » Thu Sep 08, 2011 7:02 pm

I am using 1491 and 1494

Thanks
fealldagal
 
Posts: 8
Joined: Thu Oct 29, 2009 5:31 pm

Re: Possible OpenCart Security Issue

Postby MattW » Thu Sep 08, 2011 7:15 pm

fealldagal wrote:Can someone help me i have 3 stores thank you

You should just be able to download the file from the attachment in the first post, and FTP it into your hosting and overwrite the old file.
Image
User avatar
MattW
 
Posts: 63
Joined: Sat Aug 28, 2010 3:37 am
Location: Sheffield

Re: Possible OpenCart Security Issue

Postby webpie it. » Thu Sep 08, 2011 7:17 pm

Thanks for the confirm guys!
Regards

Chris
webpie it.
 
Posts: 374
Joined: Mon Jan 31, 2011 11:28 am

Re: Possible OpenCart Security Issue

Postby fealldagal » Thu Sep 08, 2011 7:21 pm

Thnaks MattW so just upload it and it should be find correct?

Thanks
fealldagal
 
Posts: 8
Joined: Thu Oct 29, 2009 5:31 pm

Re: Possible OpenCart Security Issue

Postby MattW » Thu Sep 08, 2011 7:37 pm

fealldagal wrote:Thnaks MattW so just upload it and it should be find correct?

Thanks

Yep, that is all I've done on the 3 stores I support (all 1.4.9.6)
Image
User avatar
MattW
 
Posts: 63
Joined: Sat Aug 28, 2010 3:37 am
Location: Sheffield

Re: Possible OpenCart Security Issue

Postby FnF » Fri Sep 09, 2011 3:09 am

How insane would it be to put this important update on the OpenCart news feed? ::)
FnF
 
Posts: 79
Joined: Sat Mar 19, 2011 1:59 pm

Re: Possible OpenCart Security Issue

Postby Qphoria » Fri Sep 09, 2011 3:17 am

FnF wrote:How insane would it be to put this important update on the OpenCart news feed? ::)

Done
Image Image
Donate!|OpenCart Basics|GeoZones
Help me get more development cloud storage - Click Here to get DropBox
User avatar
Qphoria
Administrator
 
Posts: 18200
Joined: Mon Jul 21, 2008 7:02 pm
Donate to Qphoria

Re: Possible OpenCart Security Issue

Postby FnF » Fri Sep 09, 2011 4:14 am

Beautiful
Thxs, Q
FnF
 
Posts: 79
Joined: Sat Mar 19, 2011 1:59 pm

Re: Possible OpenCart Security Issue

Postby Daniel » Fri Sep 09, 2011 4:26 pm

its also php version related. not all version of php allow this hack.

php 5.3+ does not have this problem but 5.2.9 has.
OpenCart®
Project Owner & Developer.
OpenCart commercial support now available!
User avatar
Daniel
Administrator
 
Posts: 5173
Joined: Fri Nov 03, 2006 10:57 am

Re: Possible OpenCart Security Issue

Postby Xsecrets » Fri Sep 09, 2011 5:07 pm

actually I'm running 5.3.6 and the hack somewhat works on it. You can create arbitrary files, but you cannot overwrite files because the %00 doesn't work.
Xsecrets
 
Posts: 5042
Joined: Sat Oct 24, 2009 7:51 pm
Location: FL US

Re: Possible OpenCart Security Issue

Postby JoaniesGifts » Sat Sep 10, 2011 7:19 am

Thanks for letting us know guys.

Can someone post the actual code change here because we modified this file already with the @touch($file); fixes to stop the cache error in the log files.

Kind Regards, Joan
User avatar
JoaniesGifts
 
Posts: 95
Joined: Fri Oct 29, 2010 12:59 pm
Location: UK

Re: Possible OpenCart Security Issue

Postby JAY6390 » Sat Sep 10, 2011 9:51 am

ImageImageImage

Better Product SEO URL's - Perfectly structured product links
Better Category SEO URL's - Give subcategories the same SEO keyword
SEO URL's Route Editor - Fix all of your index.php links


Image
User avatar
JAY6390
 
Posts: 4634
Joined: Wed May 26, 2010 3:47 pm
Location: United Kingdom

Re: Possible OpenCart Security Issue

Postby madlime » Mon Sep 12, 2011 7:05 am

xxxxxxxxxxx
Last edited by madlime on Thu Mar 29, 2012 2:21 pm, edited 1 time in total.
http://www.madlime.com
Always Free Shipping
User avatar
madlime
 
Posts: 22
Joined: Sat May 28, 2011 9:56 am
Location: Hong Kong

Re: Possible OpenCart Security Issue

Postby Qphoria » Mon Sep 12, 2011 1:05 pm

madlime wrote:upload this file after not access admin panel ? user name and password not working

no. there is no possible way for that to happen with this file.
Image Image
Donate!|OpenCart Basics|GeoZones
Help me get more development cloud storage - Click Here to get DropBox
User avatar
Qphoria
Administrator
 
Posts: 18200
Joined: Mon Jul 21, 2008 7:02 pm
Donate to Qphoria

Re: Possible OpenCart Security Issue

Postby madlime » Mon Sep 12, 2011 5:29 pm

xxxxxxxxxxxxxx
Last edited by madlime on Thu Mar 29, 2012 2:21 pm, edited 1 time in total.
http://www.madlime.com
Always Free Shipping
User avatar
madlime
 
Posts: 22
Joined: Sat May 28, 2011 9:56 am
Location: Hong Kong

PreviousNext

Return to News & Announcements

Who is online

Users browsing this forum: Cepreu, Google Feedfetcher, Wade C and 13 guests

Hosted by Arvixe Web Hosting