About Club osCommerce

Showcasing osCommerce - the good, the bad and the ugly!

StumbleUpon It! DIGG It!

Making your shop "bulletproof"…

Written By Gary on Aug 29 2008 ·

Nice post in the offical osCommerce forum from user "Spooks" talking about security implications for osCommerce stores…

You can prevent any injection attacks with Security Pro:
http://addons.oscommerce.com/info/5752

You can monitor sites for unauthorised changes with SiteMonitor:
http://addons.oscommerce.com/info/4441

You can block elicit access attempts with IP trap:
http://addons.oscommerce.com/info/5914

You can add htaccess protection:
http://addons.oscommerce.com/info/6066

You can stop Cross Site Scripting attacks with Anti XSS:
http://addons.oscommerce.com/info/6044

Also make sure that all files, except for the two configure.php files have permissions no higher than 644. The permissions for the two configure.php files will vary according to the server your site is on - it could be 644, 444 or 400 which is correct. Permissions on folders should be no higher than 755. If your hosting setup demands permissions of 777 on folders then change hosts. You can add http://addons.oscommerce.com/info/6134 to assist with permission settings.

Do it now, avoid getting that nasty addition to your listings in google: 'This site might damage your computer' or find all your customers data has been posted on a hackers bulletin board somewhere, etc etc

Good work Spooks!


Buy Gary A Beer?
Buying me a "beer" helps me to keep my contributions updated and keep this blog alive. Cheers!


2 Comments

  1. I initially visited this blog for more information
    about the Discount Coupon….it has now become somewhat
    of an addiction. Yours is now one of the blogs/sites
    I check on a daily basis….and there's always something
    informative, useful or just plain fun-to-know waiting there.
    Much appreciated!

    Comment by Edene — August 29, 2008 @ 5:39 pm


  2. Edene - many thanks for your kind words :D

    Comment by Gary — August 30, 2008 @ 7:31 am


Leave a comment

RSS feed for comments on this post · TrackBack URL

Hot 100 osCommerce Shops

View the osCommerce HOT 100These are the best looking, most exceptional osCommerce Stores as voted for by you.

New to osCommerce - get inspiration from these beautiful shops. Reckon your site has what it takes to become a member of the HOT 100? Submit it!