Forum Moderators: buckworks

Message Too Old, No Replies

hack attacks on oscommerce

Any problems anyone?

         

Essex_boy

6:20 pm on Jun 8, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Just wondering if any one has any direct experience and has been on the receiving end from hackers when using OScommerce.

Id apreciate any advice on making the cart safer.

jatar_k

8:37 pm on Jun 9, 2003 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



I havent heard of any but the sites I know using it are very small or just for dev testing.

Where there particular things that you were worried about or thought needed addressing?

Essex_boy

9:22 pm on Jun 9, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Oh its nothing really, just that with most carts you can find a site or two telling you how expolit it etc.

I have yet to find this with OS.

just wondering thats all

jatar_k

9:26 pm on Jun 9, 2003 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



I did look around a bit looking for exactly that and couldn't find any. That's why I was wondering about specific concerns.

Maybe that is a good sign.

lorax

1:17 pm on Jun 10, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I am not aware of any specific hacks on OSC but I do know that some of the generic security issues apply - like securing your admin section, using SSL, and keeping your SID hidden from the SEs. But that's all I'm aware of.

Tangent - The OSC code keeps getting better. I'm using 2.2 MS1 and they are working on the next full release (ver 3 I think) which promises to be a much improved version. That much more hack proof I hope.

aus_dave

1:26 pm on Jun 10, 2003 (gmt 0)

10+ Year Member



I'd second what lorax said about securing your admin section. For example, if the email addresses of your members was stolen by a hacker your store would probably disintegrate along with your credibility :).

You probably know this already - use a strong password to protect the admin directory. I have also renamed the admin directory to something less obvious but that's probably not necessary unless you are paranoid.