Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
February 08, 2012, 04:10:31 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
Search:
Advanced search
The E-commerce forum, the best place for advice for your Small Business.
12254
Posts in
1447
Topics by
5625
Members
Latest Member:
NullyAccoup
E-commerce forum
E-commerce
Website development
Web site security
« previous
next »
Pages:
[
1
]
Author
Topic: Web site security (Read 488 times)
JhnStcks
Global Moderator
Part of the Furniture
Karma: 12
Offline
Gender:
Posts: 406
Web site security
«
on:
May 14, 2010, 08:42:47 PM »
Found this interesting article from the prestashop forums and thought it might be a good read for some of you.
I'm sure Scotserve will have some comments to make on it.
http://www.smashingmagazine.com/2010/01/14/web-security-primer-are-you-part-of-the-problem/
Logged
Snowboarding Goggles
For all things Snowboarding and Skiing. Goggles, Helmets, Gloves and Clothing.
The Fashion Agent
We are your fashion agent. Designer Clothes, sunglasses, headphones from top designer brands.
Baa
Member (ds)
Part of the Furniture
Karma: 23
Offline
Posts: 455
Re: Web site security
«
Reply #1 on:
May 15, 2010, 11:33:43 AM »
Good read, I'll have to look a good few of those up
thanks for the article.
Logged
You cannot conduct today's business with yesterday's methods and expect your business to grow
Moon Stag Designs
- Silver, Gold and Gemstone Jewellers. Jewellery for men, women and children.
scotserve
Guru
Shareholder ;o)
Karma: 36
Online
Gender:
Posts: 807
Re: Web site security
«
Reply #2 on:
May 15, 2010, 08:12:05 PM »
Excellent article however things are not always as easy as they seem as clients expect certain facilities and security by its very nature can intrude.
The only secure computer is one that is not plugged in.
Outdated scripts are by far the most common problem, people install shopping carts, forums and lots of different scripts and never update leaving the possibility of security holes.
Another issue from the client side is the "patching" and "add ons" found on forums, some of these are huge security risks and how can you trust the integrity of the developer, this is a major concern on open source scripts all a hacker needs to do is create a "must have add on" and install a back door giving access to every site that install the add on- ok pretty simplistic view but how many of you check the coding or indeed understand the coding of a patch you install from another forum or elsewhere. Also included here is the good intentions of someone helping get something to work, security is highly unlikely to be on the agenda.
Home security is even worse - with many people using free virus scanners also I see many people installing the likes of xampp on their home machines without realising that is turning their machine into an internet connected web server even fewer understand how to configure a firewall, a friend of mine a few years back refused to install a virus scanner saying " why i wont be storing anything on the computer" within 3 days he had 360 trojans, his machine was slowed to a snails pace cause of all the spam emails being sent via his computer, remember most hackers are not interested in what on the machine they are only interested in gaining access to control the machine turning it into a zombie computer attached to a spam network.
Logged
Scotserve - Premium Domain and Hosting services since 1994
Zola de Cwtchi
Settling In
Karma: 4
Offline
Gender:
Posts: 39
Re: Web site security
«
Reply #3 on:
May 16, 2010, 09:21:40 AM »
Yikes!
Im all paranoid and itchy now...lovely read for a sunday morning in bed, im going to put lappy down and turn over and go back to sleep!!
All these nightmare scenarios...ignorance is bliss
Logged
New Burlesque Community Forum.............
http://www.kisskissburlesque.co.uk
...come on Burlesque lovers, have a look and join up for FREE!!
JhnStcks
Global Moderator
Part of the Furniture
Karma: 12
Offline
Gender:
Posts: 406
Re: Web site security
«
Reply #4 on:
May 16, 2010, 08:52:29 PM »
Quote from: scotserve on May 15, 2010, 08:12:05 PM
Another issue from the client side is the "patching" and "add ons" found on forums, some of these are huge security risks and how can you trust the integrity of the developer, this is a major concern on open source scripts all a hacker needs to do is create a "must have add on" and install a back door giving access to every site that install the add on- ok pretty simplistic view but how many of you check the coding or indeed understand the coding of a patch you install from another forum or elsewhere. Also included here is the good intentions of someone helping get something to work, security is highly unlikely to be on the agenda.
I always have a look through coding on prestashop modules, but thats because I am interested in how they are built and how they work.
When i first started using prestashop i downloaded a theme and suddenly started getting traffic from an unknown website. After investigating the site, it was the theme developers site. Wondering how they knew I was using the theme, i had a look through their coding and they had inserted a tracking code into the theme. It only tracked which sites were using their theme, but it could have been a lot worse.
Logged
Snowboarding Goggles
For all things Snowboarding and Skiing. Goggles, Helmets, Gloves and Clothing.
The Fashion Agent
We are your fashion agent. Designer Clothes, sunglasses, headphones from top designer brands.
scotserve
Guru
Shareholder ;o)
Karma: 36
Online
Gender:
Posts: 807
Re: Web site security
«
Reply #5 on:
May 17, 2010, 12:34:35 PM »
Quote from: JhnStcks on May 16, 2010, 08:52:29 PM
Quote from: scotserve on May 15, 2010, 08:12:05 PM
Another issue from the client side is the "patching" and "add ons" found on forums, some of these are huge security risks and how can you trust the integrity of the developer, this is a major concern on open source scripts all a hacker needs to do is create a "must have add on" and install a back door giving access to every site that install the add on- ok pretty simplistic view but how many of you check the coding or indeed understand the coding of a patch you install from another forum or elsewhere. Also included here is the good intentions of someone helping get something to work, security is highly unlikely to be on the agenda.
I always have a look through coding on prestashop modules, but thats because I am interested in how they are built and how they work.
When i first started using prestashop i downloaded a theme and suddenly started getting traffic from an unknown website. After investigating the site, it was the theme developers site. Wondering how they knew I was using the theme, i had a look through their coding and they had inserted a tracking code into the theme. It only tracked which sites were using their theme, but it could have been a lot worse.
Around 9 years ago we had a client who had a shopping cart built in India, we were responsible for the hosting and installation and while installing the cart we noted that there was outgoing traffic when there should not have been, basically after investigation we found that the cart was farming off all client details including credit card info and personal information and sending it to an IP in India - luckily it was caught before the site went live, that site cost of £3k at the time to have built.
You make a valid point though John, while in your case it was only a tracker it just goes to show what can and will be inserted for the unwary
Logged
Scotserve - Premium Domain and Hosting services since 1994
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Small Business Network
-----------------------------
=> General Network Stuff .....
-----------------------------
E-commerce
-----------------------------
=> Dropship discussion
=> Dropship suppliers
=> Wholesale discussion
=> Wholesale suppliers
=> Products discussion
=> Website development
=> Shopping cart software
===> Zen cart
===> Prestashop
===> Cubecart
===> Open Cart
===> Magento
===> OsCommerce / Creload
===> Other cart software
=> SEO and marketing
=> Payment and shipping
=> Ebay and auction sites
=> Business start ups
=> Accounts and book keeping
=> General business discussions
=> Services offered
=> Services requested
-----------------------------
Social Networking
-----------------------------
=> Facebook
===> Wordpress
===> Drupal
===> DotNetNuke
===> Joomla
===> Blogger
-----------------------------
General Category
-----------------------------
=> Introductions
=> General Discussion
=> The Lounge
===> The Bar
===> Recipes
Loading...
SimplePortal 2.2.2 © 2008-2009