Why check?
osCommerce is free software for running an online shop. Many shops run old versions, and hackers look for them. A shop holds customer details, so keeping it safe matters. A regular check is like testing the locks on your doors.
Warning: take a full backup of your files and database before you change anything.
Steps
- Find your version. Log in to the admin area. The version number often shows in the footer or on the main page. Compare it to the newest release on the official osCommerce site.
- Update. If your version is old, plan an upgrade. Test it on a copy of the shop first.
- Rename the admin folder. Many shops use a folder called
admin. Rename it in File Manager to something hard to guess. Then openincludes/configure.phpin the new admin folder and update the folder name in the paths. - Protect the admin folder. Add a password to it with the Directory Privacy tool in your control panel. The shop then asks for two logins.
- Set safe file permissions. The two
configure.phpfiles should not be writable. In File Manager, set them to444(read only). Folders are usually755and files644. - Remove the install folder. If you still have an
installfolder, delete it. - Use strong passwords. Change the admin password, database password and control panel password.
- Use HTTPS. Make sure your shop uses an SSL certificate (the padlock). Set the HTTPS options in
configure.php. Ask Hostvento support if you need a certificate. - Look for odd files. Sort your folders by "Last modified". Check recent PHP files you did not add, especially in
imagesandincludes. - Check add-ons. Remove contributions (extra modules) that you do not use or that are no longer updated.
- Scan for malware. Use a scanner from your control panel or a security tool.
- Keep backups. Schedule them and store a copy off the server.
Tip: If you find a hacked file or cannot fix an issue yourself, send the details to Hostvento support using a support ticket.
Quick recap
- Know your version and keep it updated.
- Rename and password-protect the admin folder.
- Lock file permissions and delete the install folder.
- Use HTTPS, strong passwords and backups.