alphaque Posted November 5, 2006 Posted November 5, 2006 Hi I run an ebook online web store using OS commerce which customer could download the ebook immediately once their payment is made, i have implemented the Paypal IPN module in my store. Recently I noticed there are a few orders which were captured by OScommerce BUT I didn't see any related paypal payment in my paypal account. Does that mean there were hackers came to my site , download my ebook illegally without making any paypal payment ? Another oscommerce user told me he also faced the similar problem for his ebook web store, he told me once the hacker gets through paypal and returns to the site then, yes, the ebooks are available to download for the hacker but when he checked his webstats, NO files had been downloaded by the hackers. So, i am not sure whether what he said is true. Is this a flaw in the Paypal IPN ? Is there any fix for this flaw ? thanks cheers..cy Quote
satish Posted November 8, 2006 Posted November 8, 2006 Hi I run an ebook online web store using OS commerce which customer could download the ebook immediately once their payment is made, i have implemented the Paypal IPN module in my store. Recently I noticed there are a few orders which were captured by OScommerce BUT I didn't see any related paypal payment in my paypal account. Does that mean there were hackers came to my site , download my ebook illegally without making any paypal payment ? Another oscommerce user told me he also faced the similar problem for his ebook web store, he told me once the hacker gets through paypal and returns to the site then, yes, the ebooks are available to download for the hacker but when he checked his webstats, NO files had been downloaded by the hackers. So, i am not sure whether what he said is true. Is this a flaw in the Paypal IPN ? Is there any fix for this flaw ? thanks cheers..cy Download contribution checks the status tha you have set to allow download. Depending on the status a person who visits your site can hack.You need to set it for a proper payment status. Satish Mantri Quote Ask/Skype for Free osCommerce value addon/SEO suggestion tips for your site. Check My About US For who am I and what My company does.
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.