<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>ProductCart Shopping Cart Software Forums : SQL attacks or coincidence</title>
  <link>https://forum.productcart.com/</link>
  <description><![CDATA[This is an XML content feed of; ProductCart Shopping Cart Software Forums : Using ProductCart : SQL attacks or coincidence]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Sat, 11 Apr 2026 19:29:27 +0000</pubDate>
  <lastBuildDate>Sat, 11 Aug 2012 09:18:15 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forum.productcart.com/RSS_post_feed.asp?TID=5249</WebWizForums:feedURL>
  <image>
   <title><![CDATA[ProductCart Shopping Cart Software Forums]]></title>
   <url>https://forum.productcart.com/forum_images/pc_logo_50.png</url>
   <link>https://forum.productcart.com/</link>
  </image>
  <item>
   <title><![CDATA[SQL attacks or coincidence : Hamish, as a point of interest,...]]></title>
   <link>https://forum.productcart.com/sql-attacks-or-coincidence_topic5249_post20090.html#20090</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=290">Greg Dinger</a><br /><strong>Subject:</strong> 5249<br /><strong>Posted:</strong> 11-August-2012 at 9:18am<br /><br />Hamish, as a point of interest, the store where we built in a defense mechanism last month (against abuse of the contact page) was fairly current (4.1) and had CAPTCHA engaged.&nbsp; CAPTCHA did nothing to slow the attack.&nbsp; The merchant became weary of deleting e-mails and had us cut them off at 3 submissions from any given IP.]]>
   </description>
   <pubDate>Sat, 11 Aug 2012 09:18:15 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/sql-attacks-or-coincidence_topic5249_post20090.html#20090</guid>
  </item> 
  <item>
   <title><![CDATA[SQL attacks or coincidence : The Tell-A-Friend has by default...]]></title>
   <link>https://forum.productcart.com/sql-attacks-or-coincidence_topic5249_post20089.html#20089</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=303">Hamish</a><br /><strong>Subject:</strong> 5249<br /><strong>Posted:</strong> 11-August-2012 at 7:46am<br /><br />The Tell-A-Friend has by default a captcha code, unless you explicitly disable it ( in recent versions of ProductCart anyway). That should deter all but the most determined attempts at abusing the page to send messages as it needs human interaction. Its the old old story, there are so many websites out there that are vulnerable they will almost always move on to an easier target if there is a Captcha code.]]>
   </description>
   <pubDate>Sat, 11 Aug 2012 07:46:18 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/sql-attacks-or-coincidence_topic5249_post20089.html#20089</guid>
  </item> 
  <item>
   <title><![CDATA[SQL attacks or coincidence : It is fairly common that spammers...]]></title>
   <link>https://forum.productcart.com/sql-attacks-or-coincidence_topic5249_post20087.html#20087</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=290">Greg Dinger</a><br /><strong>Subject:</strong> 5249<br /><strong>Posted:</strong> 10-August-2012 at 4:44pm<br /><br />It is fairly common that spammers will attack the TAF page, exploiting it with an automated process to send spam.<DIV>&nbsp;</DIV><DIV>When they do that, it's been our practice to turn off TAF in the store, rename the file (thus hiding it) for some days until the spammer goes away.</DIV><DIV>&nbsp;</DIV><DIV>Left available for them, if they continue to exploit the page, your mail server can be blacklisted, and your site can be found to be violating your host's terms of&nbsp; use agreement.&nbsp; </DIV><DIV>&nbsp;</DIV><DIV>As a note, we recently build script modifications that allow the merchant to dictate the number of consecutively repeated uses of the contact page, and of the authorize.net page, before we redirect the offender to an error page.&nbsp; This was in response to the sorts of issues where stores are being used to test stolen credit cards, and some flake who tried to exploit a client's contact page.</DIV><DIV>&nbsp;</DIV><DIV>Both of these solutions are available for purchase if anyone needs them.</DIV>]]>
   </description>
   <pubDate>Fri, 10 Aug 2012 16:44:03 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/sql-attacks-or-coincidence_topic5249_post20087.html#20087</guid>
  </item> 
  <item>
   <title><![CDATA[SQL attacks or coincidence : Today I received three &amp;#034;Tell...]]></title>
   <link>https://forum.productcart.com/sql-attacks-or-coincidence_topic5249_post20086.html#20086</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forum.productcart.com/member_profile.asp?PF=206">M Robles</a><br /><strong>Subject:</strong> 5249<br /><strong>Posted:</strong> 10-August-2012 at 3:16pm<br /><br />Today I received three "Tell a friend" notifications hours apart for products which are random and items we never sell. I hardly ever receive TaF notifications and I find it suspicious. Should I be worried that someone is trying to get into my store?<br><br><br>]]>
   </description>
   <pubDate>Fri, 10 Aug 2012 15:16:22 +0000</pubDate>
   <guid isPermaLink="true">https://forum.productcart.com/sql-attacks-or-coincidence_topic5249_post20086.html#20086</guid>
  </item> 
 </channel>
</rss>