Post by sgdesign » Tue Nov 30, 2010 3:26 am

We are using OpenCart right now just for listing product that is available in the brick and mortar store and have no desire to sell on the web at this point.. So I commented out the add to cart functions and disabled all of the payment options..

Someone managed to place an order anyway..

A product page example:
http://www.jewelrybymorgan.com/shop/Lor ... arine-Ring

It makes me think that someone is running a script to check for OpenCart installations since a real user wouldn't be able to sort this out, I would think.. I'm not terribly worried about it, but wanted to see if anyone had any idea about what issues we should be checking because of this..

Newbie

Posts

Joined
Tue Nov 30, 2010 1:36 am

Post by i2Paq » Tue Nov 30, 2010 3:34 am

Coomenting out parts of the code will not stop the other parts from working.

I can also add items to the cart and checkout.

Have a look at: Hide add to cart button for items not in stock, this is a better solution.

Norman in 't Veldt
Moderator OpenCart Forums

_________________ READ and Search BEFORE POSTING _________________

Our FREE search: Find your answer FAST!.

[How to] BTW + Verzend + betaal setup.


User avatar
Global Moderator

Posts

Joined
Mon Nov 09, 2009 7:00 pm
Location - Winkel - The Netherlands

Post by Johnathan » Tue Nov 30, 2010 3:52 am

How did they check out if all payment gateways were disabled? They should be getting a "Error: Payment method required!" message that shouldn't let them complete the checkout process.

Image Image Image Image Image


User avatar
Administrator

Posts

Joined
Fri Dec 18, 2009 3:08 am


Post by sgdesign » Tue Nov 30, 2010 4:50 am

Jonathan, that's part of what I was trying to sort out.. I know that I had disabled everything in the checkout to keep people from ordering but after that order had been placed the COD was turned back on.. I have turned it back off again and not seen any repeat of the issue..

We've also moved to a new host and changed all passwords since then..

i2Paq, how are you going about adding product to the cart without the add to cart button?? I should do something like hide the button for items not in stock and then still allow the site to show items that are out of stock because the rules for some of the manufacturers are strange. Many manufacturers don't want their stuff sold online so we list it without a price just to show local customers that it is available..

It may make more sense to list is as "out of stock" to keep it from being added to the cart.. But then I'll need to edit out the part that says out of stock on the page because it's not really out of stock, just not available online.. Perhaps some code that says if price = 0 don't show the add to car button.. *just thinking out loud*

Newbie

Posts

Joined
Tue Nov 30, 2010 1:36 am

Post by SteveSherry » Tue Nov 30, 2010 6:16 am

I've been able to add to the cart, but have got stuck because there are no shipping methods available.

My Website ¦ Summer Madness Special Offer ¦


Active Member

Posts

Joined
Thu Apr 08, 2010 7:47 am
Location - Wirral, UK

Post by i2Paq » Tue Nov 30, 2010 7:57 pm

sgdesign wrote:Perhaps some code that says if price = 0 don't show the add to car button.. *just thinking out loud*
Did you follow the link I have in my 1st reply?

Norman in 't Veldt
Moderator OpenCart Forums

_________________ READ and Search BEFORE POSTING _________________

Our FREE search: Find your answer FAST!.

[How to] BTW + Verzend + betaal setup.


User avatar
Global Moderator

Posts

Joined
Mon Nov 09, 2009 7:00 pm
Location - Winkel - The Netherlands

Post by Johnathan » Tue Nov 30, 2010 9:58 pm

If someone knows how OpenCart works, they can still use a query string to add a product to the cart. The only way to make sure is to disable payment gateways, which sgdesign did, although it seems like the site security was compromised.

Image Image Image Image Image


User avatar
Administrator

Posts

Joined
Fri Dec 18, 2009 3:08 am


Post by sgdesign » Tue Nov 30, 2010 11:53 pm

iPaq, yes I did, and it's bookmarked for when I have 30 extra seconds to think, thank you..

Johnathan, that was my thought as well, it was the only thing I could think of..

Thanks for the help..

Newbie

Posts

Joined
Tue Nov 30, 2010 1:36 am
Who is online

Users browsing this forum: No registered users and 313 guests