Security & a few other things

[quote name=‘Unregistered’]

I have a couple of other questions if anyone could take the time please…[/quote]

Thanks for the warning :smiley:


[quote name=‘Unregistered’]

  1. Can the store be set to a location in the uk, and not have to default to Alabama ? In an earlier version I tried it did not have this feature and did indeed default to alabama (usa), which is not where I am - I’m in the uk so I want to be able to set it to uk.[/quote] No idea where you’re getting alabama from. Company details available from

    Admin / Settings / Company

    All the settings can be changed there.

    Note that this is the company ‘profile’ for the store, whereas you maybe seeing your individual user account data


[quote name=‘Unregistered’]

2) I understand that the script employs protection which includes some kind of communication with the cs-cart site / organisation. I am a little worried about this as I can’t see it being a good idea for my ecommerce website to be talking to someone behind my back. I am concidering offering the cs-cart script (licenced of course) as part of a service to some of my customers, so this worry extends beyond my own use and into being responsible for what happens to others too.

What I would like to know (and I realise you won’t want to give too many secrets away) is just what is happening - what kind of communication is going on and to what extent could that be used to exploit or otherwise compromise the cart ? What is ‘my’ cart telling cs-cart ? (or who it ‘thinks’ is cs-cart).

I know there are lots of people here who happily accept this and run their carts without worrying about it, and I guess it’s probably not such a big deal, but I really can’t just trust blind - I need to know what’s going on :)[/quote] This will be a smackdown conclusion. While it’s possible that you can remove the cs-cart backlinks this will void you license agreement as far as I know. From what I have noticed is that the script just sends a ping back to cs-cart servers everytime a certain page is loaded. This is ‘encrypted’ by base64 routines, not hard to remove but what’s the hassle if it’s legit?

I’ll leave it to you to investigate CS-Cart’s trackback links however can say that it’s never caused me an issue to date.


[quote name=‘Unregistered’]

3) Is it possible to create extra side boxes to put special offers etc in ? If so will the script automatically re-size images and such to fit the boxes ?[/quote] The grapevine tells me that this will be included in the next cs-cart release. No idea if it will be included however I do recall a conversation on the forums that states the possibility. Your request can easily be created by modifying a suitable file and including it.


[quote name=‘Unregistered’]

4) Is it possible to offer free postage for orders over a certain value, but to have postage charged by weight up to that point ? [/quote] No. I am currently speaking to CS-Cart in regards to a custom development for this.


[quote name=‘Unregistered’]

Ok - that’s lots of questions, sorry 'bout that but it’s really come time to sort these last issues out and make the final decision about whether to go with cs-cart or not. Tha above more or less should decide for me. Thanks very much

Steve[/quote] If you have to bit the bullet weigh up your options and the features included, you’ll be hardpressed to find something better value.

[quote name=‘Unregistered’]

4) Is it possible to offer free postage for orders over a certain value, but to have postage charged by weight up to that point ?

[/QUOTE]





Yes you can.

[quote name=‘JesseLeeStringer’]While it’s possible that you can remove the cs-cart backlinks this will void you license agreement as far as I know. [/QUOTE]





Are you sure about this…because I don’t see it anywhere in the license posted on the CS cart website (link here). Now i’m nervous because I did remove some links and references to CScart while editing the templates. There are quite a few backlinks to them actually…so it would help to know what links we can remove, and which are required to stay.



Anyone know the specifics?

I got rid of all mine. Except the hidden cookie.

[quote name=‘Dreamshop’]Are you sure about this…because I don’t see it anywhere in the license posted on the CS cart website (link here). Now i’m nervous because I did remove some links and references to CScart while editing the templates. There are quite a few backlinks to them actually…so it would help to know what links we can remove, and which are required to stay.



Anyone know the specifics?[/quote]

I wouldn’t worry about it all that much, there is one biggy which is located on the admin side which most people will proberly never find, it’s not part of the skins so there should’nt be any issues with regards to the links.


[quote name=‘Zyles’]Yes you can.[/quote]

Zyles, Please show me mate?

If you’ve got more then one shipping method, when items are over the $100 mark, predetermined weight cost dependancies are added.

[quote name=‘Zyles’]Yes you can.[/quote]



Zyles, Please show me mate?

If you’ve got more then one shipping method, when items are over the $100 mark, predetermined weight cost dependancies are added.

[quote name=‘JesseLeeStringer’]

Zyles, Please show me mate?

If you’ve got more then one shipping method, when items are over the $100 mark, predetermined weight cost dependancies are added.[/QUOTE]



Oh yeah, I think you’re right. I was thinking about another method but realized you can’t flip between them.

Security patches are released as solo upgrades to address any flaws immediately, as well, as they email all customers about the flaw and the fix for it.



SP3 and such are bug fixes and functionality additions, not security flaw fixes.





The callback to cscart is just a “ping” they transfer no confidential data that I have been told, they just validate the license keys.