Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

Behavior of OSC / PHP - Can someone confirm ?


Mort-lemur

Recommended Posts

Posted

Hi,

 

I thought I had been hacked as I was getting some strange messages in my Control panel error log, so I posted on the security forum. Turns out that my site is OK, but Im puzzled by this and would like someone to try it for me and let me know the results.

 

Via admin edit a product that does not have an image, preview and save the product.

 

Now log into your Host control panel, look at the error logs and see if there are any errors generated.

 

Many Thanks

Now running on a fully modded, Mobile Friendly 2.3.4 Store with the Excellent MTS installed - See my profile for the mods installed ..... So much thanks for all the help given along the way by forum members.

Posted
Now log into your Host control panel, look at the error logs and see if there are any errors generated.

could you post the logs here, if it's possible? are they php warnings or errors?

Please read this line: Do you want to find all the answers to your questions? click here. As for contribution database it's located here!

8 people out of 10 don't bother to read installation manuals. I can recommend: if you can't read the installation manual, don't bother to install any contribution yourself.

Before installing contribution or editing/updating/deleting any files, do the full backup, it will save to you & everyone here on the forum time to fix your issues.

Any issues with oscommerce, I am here to help you.

Posted

Hi Alex,

 

I posted these in the security thread, as I thought I was hacked first time round. Thread HERE Looks like my site is ok - so now Im curious to why this is happening.

 

What seems to be happening is that when I try to edit a product with no image, osc looks for a landing page in the images directory and I get the errors below (these were some of the logs when I used X sell, but I get the same thing when just editing a product with no image):

 

[sun Sep 26 20:40:15 2010] [error] [client 88.106.40....] client denied by server configuration: /home/user/public_html/images/default.html, referer: https://www.mysite.c...admin/xsell.php

 

[sun Sep 26 20:40:15 2010] [error] [client 88.106.40....] client denied by server configuration: /home/user/public_html/images/index.phtml, referer: https://www.mysite.c...admin/xsell.php

 

[sun Sep 26 20:40:15 2010] [error] [client 88.106.40....] client denied by server configuration: /home/user/public_html/images/index.php, referer: https://www.mysite.c...admin/xsell.php

 

[sun Sep 26 20:40:15 2010] [error] [client 88.106.40....] client denied by server configuration: /home/oser/public_html/images/index.php3, referer: https://www.mysite.c...admin/xsell.php

 

As you can see OSC is lookig for different names of Index or home to land on as there is no image.

 

Now this is not a great problem to me, apart from the way I have my security set up - which means that I get my IP banned every time I try this.

 

I have put in a work around by installing a blank image to products with no real image. But I was curious if this was how everyone elses OSC worked, or if it is something perculiar with my set up.

Now running on a fully modded, Mobile Friendly 2.3.4 Store with the Excellent MTS installed - See my profile for the mods installed ..... So much thanks for all the help given along the way by forum members.

Posted
Now this is not a great problem to me, apart from the way I have my security set up - which means that I get my IP banned every time I try this

 

looking on the log and the whole issue:

1) why the script looking into incorrect folder or files which doesn't exist.

2) why the banning script logging the IP addresses which looking up for missing file, if your customer mistype once the URL your script automatically ban the client? I can say very strange configuration.

Please read this line: Do you want to find all the answers to your questions? click here. As for contribution database it's located here!

8 people out of 10 don't bother to read installation manuals. I can recommend: if you can't read the installation manual, don't bother to install any contribution yourself.

Before installing contribution or editing/updating/deleting any files, do the full backup, it will save to you & everyone here on the forum time to fix your issues.

Any issues with oscommerce, I am here to help you.

Posted

Hi,

 

My point exactly, why when OSC can't find an image does it go off into the images folder and look for a landing page?

 

This only happens when working on products with no images.

 

The security is OK as my images .htaccess is blocking attempts to run php scripts from within the images directory.

 

thanks

Now running on a fully modded, Mobile Friendly 2.3.4 Store with the Excellent MTS installed - See my profile for the mods installed ..... So much thanks for all the help given along the way by forum members.

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...