vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Modification Graveyard (https://vborg.vbsupport.ru/forumdisplay.php?f=224)
-   -   Major Additions - microCART: Shopping System for vB4 (https://vborg.vbsupport.ru/showthread.php?t=256723)

BirdOPrey5 05-26-2014 10:34 AM

Quote:

Originally Posted by Toorak Times (Post 2499080)
I got this from my host


Hi Mick,


Are you using the microcart installation?

This has a file management tool kcfinder which has many known security
vulnerabilities.

http://www.tooraktimes.com.au/microc...der/browse.php -> allows you to
upload and browse the files in public_html/microcart/kcfinder/upload/files
directory.


Check this link
http://packetstormsecurity.com/files...ll-Upload.html


The hacker uploaded a shell script and tried to scan all other configuration
files in the server. I am disabling that microcart link.


root@experience [/usr/local/maldetect/sess]# more
session.hits.052214-1739.1040785
{HEX}gzbase64.inject.unclassed.15 :
public_html/microcart/kcfinder/upload/files/b.php5



Your host said the URL to kcfinder was:
Code:

http://www.tooraktimes.com.au/microcart/kcfinder/browse.php
But there is no /kcfinder/ directory in this mod's zip file... Not sure how or why you have a /kcfinder/ directory but it doesn't appear to be included with this mod.

Toorak Times 05-26-2014 10:45 AM

So BOP, when I was hacked by TH3 HACK3R could they have installed it in the cart then? I saw a reference to Black Hack3r in files. I have tried to uninstall this mod but it crashed my site so I have isolated it. I wish Michael would reply as this is really stressing me out

BirdOPrey5 05-26-2014 02:58 PM

Quote:

Originally Posted by Toorak Times (Post 2499452)
So BOP, when I was hacked by TH3 HACK3R could they have installed it in the cart then? I saw a reference to Black Hack3r in files. I have tried to uninstall this mod but it crashed my site so I have isolated it. I wish Michael would reply as this is really stressing me out

It's certainly possible... I would suggest anyone with this mod installed check for a /kcfinder/ directory in their /microcart/ directory, just to be sure.

At this point all I know for sure is /kcfinder/ does not come as part of this mod. I can't say whether an exploit in this mod allowed it to be uploaded or an exploit it something else did.

Toorak Times 05-26-2014 03:46 PM

Quote:

Originally Posted by BirdOPrey5 (Post 2499480)
It's certainly possible... I would suggest anyone with this mod installed check for a /kcfinder/ directory in their /microcart/ directory, just to be sure.

At this point all I know for sure is /kcfinder/ does not come as part of this mod. I can't say whether an exploit in this mod allowed it to be uploaded or an exploit it something else did.



I got smashed 5 times BOP, my database is still psychopathic. have a look if you like...PLEASE!!!

BirdOPrey5 05-26-2014 10:07 PM

Quote:

Originally Posted by Toorak Times (Post 2499493)
I got smashed 5 times BOP, my database is still psychopathic. have a look if you like...PLEASE!!!

I would suggest you look for .php files in the following directories- I've found them in these directories while cleaning up hacked sites before (check all sub-folders of these folders as well)-

/customavatars
/customgroupicons
/customprofilepics
/images
/signaturepics

If you have attachments stored in a web accessible location check that folder too.

These folders should not contain .php files.

As for being in your database the only real place they could be is in a plugin. Check and make sure you don't have any plugins listed in Plugin Manager (not product manager) at the top listed under the "vBulletin" product. If you do make sure these are plugins you created yourself and double-check the code. This is the most often exploited spot.

Second most exploited in my experience is hidden as a plugin of Forum Runner but this will be cleaned if you re-run the upgrade script which I recommend you do if you've been hacked.

Any 3rd party products should be re-installed after a hack to make sure their plugins are the original values and don't contain backdoors left by the hacker.

Toorak Times 05-27-2014 03:08 AM

Thank you so much mate, awesome

AwesomeMetalB 10-16-2014 06:36 PM

Hello,

Regarding the post about:

The fix I use is, go to: Admin CP > Settings > Options > Site Name / URL / Contact Details
In the 'Redirect Domain Whitelist' field, add:
<a href="https://www.paypal.com/" target="_blank">https://www.paypal.com</a>
<a href="https://www.sandbox.paypal.com/" target="_blank">https://www.sandbox.paypal.com</a>


I have implemented this and still receive the following error

Invalid Redirect URL (https://www.paypal.com/cgi-bin/websc...ethod%3Dpaypal)

please see screenshot

http://tinypic.com/r/25icgtk/8

Thank you

Daniel

amandatx 10-16-2014 08:16 PM

1 Attachment(s)
Hello,

After the install I 'am only accessing the index page. Please see the attachment. Any solutions?

Thanks in advance.

AwesomeMetalB 10-16-2014 08:37 PM

cart.php and cart_gateway.php need to be in the same directory as forum.php

for me its /public_html

see if thats the answer

amandatx 10-16-2014 09:07 PM

Quote:

Originally Posted by AwesomeMetalB (Post 2519099)
cart.php and cart_gateway.php need to be in the same directory as forum.php

for me its /public_html

see if thats the answer

Thanks for the reply. I've moved the files, not seeming to have any effect.

Thanks again.

AwesomeMetalB 10-16-2014 09:11 PM

Right I solved my problem about the "Invalid Redirect URL"

https://www.paypal.com


Just like that without the html code, its very frustrating when people post here and dont post the exact answer they have some weird formating and expect you to spend hours decoding it like hieroglyphics.

when you go to options, Site Name / URL / Contact Details. Redirect Domain Whitelist

its simply

https://www.paypal.com

and that should direct the page to the paypal payment page


Daniel of Awesomemetalbands.com

AwesomeMetalB 10-16-2014 09:14 PM

amandatx,

stupid question you obviously have Vbullitin installed? can you go to your forum? do you see a new tab called e shop?

Daniel

AwesomeMetalB 10-16-2014 09:16 PM

you are more then welcome to discuss this with me on AMB, i am very new to MicroCART, but would be great to exchange ideas

http://awesomemetalbands.com/metalchat.php

amandatx 10-16-2014 09:47 PM

Quote:

Originally Posted by AwesomeMetalB (Post 2519102)
amandatx,

stupid question you obviously have Vbullitin installed? can you go to your forum? do you see a new tab called e shop?

Daniel

Yes, I have vBulletin installed. No, there is no tab labeled e shop associated with the forum nor the server.

Muhammad Rahman 10-16-2014 11:17 PM

can member add product??

amandatx 10-16-2014 11:53 PM

Quote:

Originally Posted by Muhammad Rahman (Post 2519107)
can member add product??

No. Can't get pass the index screen.

Muhammad Rahman 10-17-2014 11:21 PM

Quote:

Originally Posted by amandatx (Post 2519108)
No. Can't get pass the index screen.

thanks for information :)

amandatx 10-18-2014 05:29 PM

We're up and running! This mod is out of site/sight! :)!

AwesomeMetalB 10-22-2014 09:48 AM

Hello,

Discount doesn't show until item quantity is changed? How can this be rectified, apologies if this has already been posted.

Huw Thomas 11-21-2014 07:06 AM

Is it possible to use paypal pro for normal paypal and credit card processing instead of just the standard paypal which take the user away form the website? We are using this Haddon but many customers payments aren't being registered when the customer doesn't return to the website after completing their payment with paypal.

Any suggestions would be greatly appreciated.

Thanks
Huw

TheAdminMarket 12-26-2014 02:08 PM

Is anybody interested for an update release of this mod? If yes, then click Like or post a comment below.

Johnny G 12-26-2014 05:53 PM

100% yes

TheAdminMarket 12-26-2014 05:55 PM

Quote:

Originally Posted by Johnny G (Post 2528899)
100% yes

Just downloadable products is ok for you or do you need the support for tangible products?. I'm talking for the exact same script, but currently I've removed the tangible products to make the code more solid.

TheAdminMarket 12-26-2014 05:58 PM

@Johnny G

Seen that you're in EU. Some great knews. It'll support EU VAT with auto VAT id validation.

TheAdminMarket 12-27-2014 09:30 AM

1 Attachment(s)
Hello,

Finally I decided to post the update here and not as a seperate mod as in my version I don't support tangible products. But I'll continue updating this version for any bug fixes.

I've named this version 2.0.0 to be visible seperated from 1.x versions. In this version I've added/fixed:
  1. Fixed several design issues especially with sidebar
  2. Added Tab Menu to support the new vb Navigation manager
  3. Added to all php files the code: define('SKIP_ALL_ERRORS', true); to skip all waring messages. I suggest to add this line to your config.php at the top (just after <?php).
  4. Corrected the HTML editor to take the full width space when you're adding/editing products
For someone who was getting error trying to import images in the HTML editor, he must set the correct paths in file: microcart/editor/assetmanager/settings.php

To update your installation:
  • Upload microcart_admin.php to your admincp directory
  • Upload functions.php at microcart/
  • Upload cart.php at your forum directory
  • Import product-microcart_v200_27Dec2014.xml and don't forget to select "Overwite".
If you've to report any other bugs feel free to do it here. I'm not always on this site but I'll try to visit it in a regular basis. Please don't PM for bugs. Post them here.

I wish to all a Happy and Prosperous New Year. Health, Happiness, Success to all of you and to your beloved persons. And for sure Peace for the world.

Johnny G 12-27-2014 01:52 PM

Quote:

Originally Posted by NickTheGreek (Post 2528900)
Just downloadable products is ok for you or do you need the support for tangible products?. I'm talking for the exact same script, but currently I've removed the tangible products to make the code more solid.

I would like tangible, physical products. But, not to worry, needs of the many vs the needs of the few :D
Thanks anyways!!

TheAdminMarket 12-27-2014 02:21 PM

Quote:

Originally Posted by Johnny G (Post 2529026)
I would like tangible, physical products. But, not to worry, needs of the many vs the needs of the few :D
Thanks anyways!!

I've post some files with bug fixes and design issues that I found. They're on my last post in previous page. Sorry but there is no other way to release them.

Johnny G 12-27-2014 02:30 PM

I'm sure I speak for many people when I thank you for your efforts.

TheAdminMarket 12-28-2014 07:32 AM

Quote:

Originally Posted by Johnny G (Post 2529038)
I'm sure I speak for many people when I thank you for your efforts.

Finally I'll include tangible products too, but the final mod should be commercial with a small fee. As you're using it for tangible products please tell me something. In data table there are fields for Product code and Manufacturer but I can't find them in the form. Have been removed? As I remember these fields were there.

TheAdminMarket 01-01-2015 06:41 AM

@Johnny G

Happy and Prosperous New Year :)

If you want you can give a look at: http://www.phpkiosk.com/demo/vb4x/cart.php

demouser1
demopass1

For testing EU VAT and Shipping do the follow tests during Checkout (for testing purposes assumes that Shop is locating in Greece).

1.- Select United Kingdom as Location. You'll see that if you set a valid EU-GB VAT id the VAT should be 0. If you left it empty or your auto check fails (invalid VAT id) you'll debit with VAT 20% according to the new EU rules (Customer's country and not Seller's country).

2.- Change the location to Greece. Now, with or without a valid VAT id you'll be debited with VAT 20%

3.- Last change the location to United States and you'll see that none VAT will be debit.

Johnny G 01-01-2015 12:25 PM

Quote:

Originally Posted by NickTheGreek (Post 2529126)
Finally I'll include tangible products too, but the final mod should be commercial with a small fee. As you're using it for tangible products please tell me something. In data table there are fields for Product code and Manufacturer but I can't find them in the form. Have been removed? As I remember these fields were there.

Quote:

Originally Posted by NickTheGreek (Post 2529820)
@Johnny G

Happy and Prosperous New Year :)

If you want you can give a look at: http://www.phpkiosk.com/demo/vb4x/cart.php

demouser1
demopass1

For testing EU VAT and Shipping do the follow tests during Checkout (for testing purposes assumes that Shop is locating in Greece).

1.- Select United Kingdom as Location. You'll see that if you set a valid EU-GB VAT id the VAT should be 0. If you left it empty or your auto check fails (invalid VAT id) you'll debit with VAT 20% according to the new EU rules (Customer's country and not Seller's country).

2.- Change the location to Greece. Now, with or without a valid VAT id you'll be debited with VAT 20%

3.- Last change the location to United States and you'll see that none VAT will be debit.

Wow. Many thanks!!
I'll have a look this weekend :D

TheAdminMarket 01-06-2015 05:18 PM

Quote:

Originally Posted by Johnny G (Post 2529845)
Wow. Many thanks!!
I'll have a look this weekend :D

Finished :)

Gadget_Guy 01-08-2015 02:33 AM

I would be very interested in this mod to sell tangible products on my site (we sell our club branded items like stickers and mugs to raise money for charity).

I am located in Canada and my members are Canadian.

Paypal for payment is perfect.

Any chance there would be a way to interface with Canada Post whom we use for shipping?

They have a module for this that I use with Zen Cart, but my users hate having to leave the site to use zencart to order stuff.

I'd be willing to do testing with you if that helps.

D.

JesWhite 01-08-2015 05:53 AM

Quote:

Originally Posted by NickTheGreek (Post 2528993)
Hello,

Finally I decided to post the update here and not as a seperate mod as in my version I don't support tangible products. But I'll continue updating this version for any bug fixes.

I've named this version 2.0.0 to be visible seperated from 1.x versions. In this version I've added/fixed:
  1. Fixed several design issues especially with sidebar
  2. Added Tab Menu to support the new vb Navigation manager
  3. Added to all php files the code: define('SKIP_ALL_ERRORS', true); to skip all waring messages. I suggest to add this line to your config.php at the top (just after <?php).
  4. Corrected the HTML editor to take the full width space when you're adding/editing products
For someone who was getting error trying to import images in the HTML editor, he must set the correct paths in file: microcart/editor/assetmanager/settings.php

To update your installation:
  • Upload microcart_admin.php to your admincp directory
  • Upload functions.php at microcart/
  • Upload cart.php at your forum directory
  • Import product-microcart_v200_27Dec2014.xml and don't forget to select "Overwite".
If you've to report any other bugs feel free to do it here. I'm not always on this site but I'll try to visit it in a regular basis. Please don't PM for bugs. Post them here.

I wish to all a Happy and Prosperous New Year. Health, Happiness, Success to all of you and to your beloved persons. And for sure Peace for the world.

if i install MICROCART_114_16_05_2011a.zip and after that i use your patch is this patch work?

thanks again...

TheAdminMarket 01-08-2015 08:30 AM

Quote:

Originally Posted by JesWhite (Post 2531164)
if i install MICROCART_114_16_05_2011a.zip and after that i use your patch is this patch work?

thanks again...

Yes, it should works. But if you wait some hours I'll release here this version:
http://demo.teriakis.com/vb4x/cart.php
You can find testing account login in header.

Has fixed all bugs of microCART and added some new features. The reason that I changed the name is because there are 2 versions of microCART and I wanted to avoid a system mess.

Later on and if I see that there are active installation of microCART (I don't think so with so many bugs that I found), I'll release a data importer.

Johnny G 01-08-2015 09:09 PM

Nick, superb effort :D

ozzy47 01-08-2015 09:10 PM

Quote:

Originally Posted by Johnny G (Post 2531347)
Nick, superb effort :D

Newest version is here, https://vborg.vbsupport.ru/showthread.php?t=316501
But wait till the developer fixes a bug with the tables in the DB.

Johnny G 01-08-2015 09:14 PM

I've just seen it, thanks :)

ozzy47 01-09-2015 10:06 AM

And the bug is now fixed in the other version. :)

eh69 02-03-2015 05:51 PM

<a href="https://technidev.com/microcart-1-1-4-arbitrary-files-deletion-sql-injection-xss/" target="_blank">https://technidev.com/microcart-1-1-...injection-xss/</a>

Can I please for fix for this?


All times are GMT. The time now is 10:17 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03060 seconds
  • Memory Usage 1,849KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_code_printable
  • (18)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (1)pagenav_pagelinkrel
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete