Praise from...
| Craig L. Grantham |
| BRILLIANT! STUPENDOUS! AWESOME! PERFECT!!! You know Frank – I'm still amazed at how well we communicate intricate details on Web site building with nothing more than e-mail...you're a great communicator! Craig L. Grantham, Founder Kneeriders.com. |
| Preventing osCommerce Admin exploits |
|
|
|
| Tips & Tricks | |||
|
One such exploit allowed hackers to gain access to osCommerce's Mass Mail tool and send spam to every email address in the database's "customers" table. It turns out that by adding an admin-page file name to the login URL, a hacker could see and use that page. In the case of Mass Mail, all a hacker had to do was append the login URL in his browser by changing http://www.yoursite.com/admin/login.php to http://www.yoursite.com/login.php/mail.php. He could then see and abuse the Mass Mail page to send spam. To fix this, osCommerce site owners and managers should take the following steps:
For additional info on this exploit, visit the thread Serious Hole Found in osCommerce at the osCommerce forums. Frank Nilsen January, 2010
|




Though