YazminMedia
Helping You Grow Online
  • See What I Can Do For You
  • Learn More About Me
  • Portfolio
  • Hire Me For Your Next Project
  • Blog

Patch Notice: Zen Cart Security Vulnerability + Patch

No Comments Posted in: News, Off-Topic | June 29, 2009

This weekend, I received the following email from the Zen Cart folks. If you are running Zen Cart, you’ll definitely want to make sure you read this:

Please pardon this mass email. If you are running a Zen Cart store, it’s important that you read this message and take action immediately.

A vulnerability has been discovered in the admin section of v1.3.8 (and previous versions). To take advantage of this vulnerability any attacker must know the URL of your admin section. As our security recommendations point out, you should change the folder that your admin resides in as soon as you installed Zen Cart.

SO — THE FIRST STEP YOU **NEED** TO TAKE is to rename your /admin/ folder!
http://tutorials.zen-cart.com/index.php?article=33

However we realise that relying on this ‘Security through Obscurity’ is not foolproof, hence the release of a patch, which can be downloaded from the Zen Cart Support forum, here: http://www.zen-cart.com/forum/showthread.php?t=130161

The zip file there contains a readme.html with full details on how to install the security patch files. The security patch uses Zen Cart’s override system to make installation as simple as possible.

The security patch will work for previous versions in the 1.3.x series.

Older releases i.e v1.2.x are no longer supported and the patch has not been fully tested on those versions, however some parts of the patch should still work with v1.2.x (again see the readme.html file). However we strongly advise anyone using the 1.2.x versions to upgrade to 1.3.8 as soon as possible.

The Zen Cart Team takes security matters very seriously. But security is only as good as those who follow posted recommendations. Please apply the appropriate patches and security measures promptly, for your own benefit.

SUMMARY: Your Action Steps are:

1. RENAME YOUR ADMIN FOLDER !!!!!
Yes, if you haven’t already renamed your /admin/ folder, do it NOW!
Instructions can be found here: http://tutorials.zen-cart.com/index.php?article=33

2. APPLY THE SECURITY PATCH !!!
http://www.zen-cart.com/forum/showthread.php?t=130161

3. Subscribe yourself to the Zen Cart Announcements mailing list:
http://www.zen-cart.com/forum/subscription.php?do=addsubscription&f=2

4. Keep your site’s Zen Cart software up-to-date at all times. Numerous bugs, improvements, and security fixes are included in every new release. It is in your best interests to remain current.
http://www.zen-cart.com/forum/forumdisplay.php?f=2

Sincerely,

The Zen Cart Team

Make sure you keep your software patched and up-to-date to avoid hacking! If you need help updating your software, contact me today!This weekend, I received the following email from the Zen Cart folks. If you are running Zen Cart, you’ll definitely want to make sure you read this:

Please pardon this mass email. If you are running a Zen Cart store, it’s important that you read this message and take action immediately. A vulnerability has been discovered in the admin section of v1.3.8 (and previous versions). To take advantage of this vulnerability any attacker must know the URL of your admin section. As our security recommendations point out, you should change the folder that your admin resides in as soon as you installed Zen Cart. SO — THE FIRST STEP YOU **NEED** TO TAKE is to rename your /admin/ folder! http://tutorials.zen-cart.com/index.php?article=33 However we realise that relying on this ‘Security through Obscurity’ is not foolproof, hence the release of a patch, which can be downloaded from the Zen Cart Support forum, here: http://www.zen-cart.com/forum/showthread.php?t=130161 The zip file there contains a readme.html with full details on how to install the security patch files. The security patch uses Zen Cart’s override system to make installation as simple as possible. The security patch will work for previous versions in the 1.3.x series. Older releases i.e v1.2.x are no longer supported and the patch has not been fully tested on those versions, however some parts of the patch should still work with v1.2.x (again see the readme.html file). However we strongly advise anyone using the 1.2.x versions to upgrade to 1.3.8 as soon as possible. The Zen Cart Team takes security matters very seriously. But security is only as good as those who follow posted recommendations. Please apply the appropriate patches and security measures promptly, for your own benefit. SUMMARY: Your Action Steps are: 1. RENAME YOUR ADMIN FOLDER !!!!! Yes, if you haven’t already renamed your /admin/ folder, do it NOW! Instructions can be found here: http://tutorials.zen-cart.com/index.php?article=33 2. APPLY THE SECURITY PATCH !!! http://www.zen-cart.com/forum/showthread.php?t=130161 3. Subscribe yourself to the Zen Cart Announcements mailing list: http://www.zen-cart.com/forum/subscription.php?do=addsubscription&f=2 4. Keep your site’s Zen Cart software up-to-date at all times. Numerous bugs, improvements, and security fixes are included in every new release. It is in your best interests to remain current. http://www.zen-cart.com/forum/forumdisplay.php?f=2 Sincerely, The Zen Cart Team

Make sure you keep your software patched and up-to-date to avoid hacking! If you need help updating your software, contact me today!

← Long time, no post…
Have a Happy 4th of July! →

Leave a Reply

Click here to cancel reply.

Post Comment

CommentLuv badgeShow more posts

Connect

Follow Me on flickrFollow Me on linkedinFollow Me on twitterFollow Me on wordpress

Popular Posts

  • New Site Completed: BestGIJoeCostumes.com
    New Site Completed: BestGIJoeCostumes.com September 15, 2009
  • I’m Guilty
    I’m Guilty July 13, 2010
  • WordCamp Atlanta 2012 – An Eye-Opener
    WordCamp Atlanta 2012 – An Eye-Opener February 6, 2012

I Recommend…

AdvertisementAdvertisementAdvertisementAdvertisement

Tags

4th of July Add-ons Adoption american flag Best Star Trek Costumes Blog Management Business Blogging CAPTCHA Church cobwebs Comment Spam contractors Costumes Digitize elevator pitch Family By Faith Worship Center fireworks Flash food photography fouth of July goals Google Chrome Halloween kia soul kia soul videos LMFAO mission statement music video mysql OCR paypal labels paypal shipping photography PHP Plug-ins project management redesign Textpattern tip Translation updates web prescence Wordpress Writing your own website

Archives

  • May 2012 (1)
  • April 2012 (4)
  • March 2012 (3)
  • February 2012 (2)
  • January 2012 (1)
  • September 2011 (1)
  • August 2011 (1)
  • July 2011 (3)
  • August 2010 (2)
  • July 2010 (3)
  • November 2009 (1)
  • September 2009 (3)
  • July 2009 (4)
  • June 2009 (2)
  • January 2008 (1)
  • June 2007 (1)
  • June 2006 (1)
  • October 2005 (1)
  • September 2005 (1)
  • July 2005 (2)
  • June 2005 (2)

Stay updated!

Join our mailing list. No spam. That's a promise!
* = required field

Flickr

Contact

  • Phone: +1 678.807.9676
  • Fax: +1 678.298.7524

Connect

Follow Me on flickrFollow Me on linkedinFollow Me on twitterFollow Me on wordpress
©2012 YazminMedia