-
Posts
359 -
Joined
-
Last visited
-
Days Won
11
Content Type
Profiles
Forums
Gallery
Downloads
Articles
Store
Blogs
Everything posted by Acer
-
Hi I'm sure many of us are wondering how Lesley is doing? Can we have an update please?
-
Yeah, any news on @lesley? I'm sure we're all curious how he's doing? Best wishes to Lesley and for a speedy recovery.
-
[SECURITY] Serious PrestaShop Security Vulnerability and TB?
Acer replied to Acer's topic in Announcements about thirty bees
Thanks @lesley and @Traumflug for the feedback here And for the original DH42 email (Lesley) ๐ -
[SECURITY] Serious PrestaShop Security Vulnerability and TB?
Acer replied to Acer's topic in Announcements about thirty bees
As @Traumflug mentioned, search for a folder with the name phpunit if you find it, you can delete the phpunit folder and all its content. Also, I think it's safe to assume that "upgraded PS 1.6 to TB sites" could be at risk here also. -
[SECURITY] Serious PrestaShop Security Vulnerability and TB?
Acer replied to Acer's topic in Announcements about thirty bees
Right, obviously. Lol... I think when something like this comes up, it's easy to panic automatically and risk not seeing things 100%. To quote myself: ๐ -
[SECURITY] Serious PrestaShop Security Vulnerability and TB?
Acer replied to Acer's topic in Announcements about thirty bees
If there are no folders, but the phpunit.xml file comes up? vendor\greenlion\phpunit.xml vendor\swiftmailer\phpunit.xml -
[SECURITY] Serious PrestaShop Security Vulnerability and TB?
Acer replied to Acer's topic in Announcements about thirty bees
Ummm. I think the TB admin guys need to reply here pls... Just doing a quick search on my local TB 1.1.0 install and I'm getting phpunit.xml in multiple locations. @GotaborTry doing a search just for the file "phpunit.xml" and see if something comes up? TB admins, some feedback pls? -
Hi I've received a mail for DH42 about a new PrestaShop Security Vulnerability that affects all versions of PS. Can you guys please inform us if this applies to TB? This is the "more info" doc from PS https://docs.google.com/document/d/1D76Lj93gw-XZ8GgV8UzK6Oi6u5qLxLDEsC2298Go-as/edit#heading=h.tjhj04l5p8kk
-
Hi @rubben1985 Nope, as mentioned in this post, Panda+TB+LiteSpeed cache does not work together at the moment. I've reached out to both developers (Panda+LiteSpeed) and they've mentioned that they would like to fix this eventually. However, as they are both pretty busy I'm not sure when this will be. Will update this thread when I hear more.
-
Just an update on this: Awesomely, both @Jonny and Lauren from LiteSpeed have shown willingness to make TB Panda compatible with the LiteSpeed plugin! ๐ Big thanks in advance to both of them. It now all depends on workload on their sides, as they are both currently focused on other projects. Will update this post when I've heard of any progress.
-
It's worth experimenting. But I'm not sure if it will work. One thing that I did notice is that it caches the user name that is logged in (in the top bar, front-end, shop side). So I'm not sure if telling LSCache to not cache the 'Login' module will stop this from happening. Either way, I'm waiting to hear back from @Jonny and the plugin developer.
-
Alas... ๐คจ It appears we celebrated a bit too early on this one... So my initial testing was done on a quick test site - and at first everything appeared to be working... Unfortunately when I did testing with an actual production / Live site, I discovered it's actually not compatible. LiteSpeed plugin caches the crap out of Panda. Stuff like user logged in, cart etc. are all cached. Yes it's blazing fast - but it's not working. Apparently Panda needs to be modified to handle LiteSpeed. I've reached out to the LiteSpeed plugin author and she appears to be willing - but has other priorities to wrap up first. At the same time, I've reached out to @Jonny to check his willingness & availability. Will update this thread when I know more. Perhaps someone here has been able to make Panda compatible with LiteSpeed? Bytw: A side benefit of being on a LiteSpeed server (even without the plugin), is that the server is natively faster than Apache/Nix. Also, when you're on a LiteSpeed server, it comes with a modified and optimised LiteSpeed version of Memcached. When this is enabled (both in PHP options and TB caching settings) you get a speed boost anyway. No, not 'light speed', but it certainly is close.
-
Ok cool, will implement, thank you.
-
Perhaps you're right. However, I couldn't find the entry in question ('page') using phpMyAdmin (it's not in tb_meta). So before I just added a new entry to the table, I refreshed - and all was good. Or so it seemed. So should I add an entry to tb_meta table for 'page' or is it in another table somewhere? (I'm on 30Bz 1.1.0)
-
Bytw: in my case (also a Panda issue), I did not have to implement the MySQL update. Just thought I'd let you know. Just implemented the changes to Meta.php and problem went away. Thank you
-
Hi Movieseals Thanks for the feedback here. I've given it a shot and all appears to be working (the headers are reporting Litespeed as they should) + really fast page loads ๐ Thanks again
-
Pedalman, please update the link (I think it's linking to your shop). This is exactly what I was interested in - will check it out, thanks! Any other suggestions guys?
-
Hi guys I'm trying to install TB 1.1.0 on a new server, but I'm getting this error (Paypal, can't proceed with Next). Installed TB 1.1.0 on two other different hosts, and this is the first time I'm seeing this... Following the instructions to modify ConfigurationTest + Configuration hasn't worked.... Can you please share instructions on how to quickly fix this? As I see there's been a lot of activity on this post - not sure which is the solution / magic bullet? Thanks
-
Thanks for the reply. Are there any hardening tools available? Like Akeeba admin tools - Joomla, Sucuri monitor - WordPress etc for TB / PS 1.6?
-
Please see original post. How do we prevent this, are there hardening tools or techniques available? Also as there will likely be changes to files anyway as part of the course of normal development, as you say as well, the core updater will not be useful here. And checking manually is not practical... Any suggestions, thoughts and ideas re this and 30Bz site security?
-
Ok interesting. I think it the Business edition. The reason I'm asking is that apparently it only works with "the default theme + warehouse" and I've seen other TB guys ask on the Litespeed forums how to make it work... Are you using Warehouse, or which theme?
-
Hi So the Magecart thing was one scary thing (for Magento) - now there are reports that there is a Presta 'hack' that bypasses / or fakes the 'flyover' for a third-party payment gateway... Scary. I wonder how the site was infiltrated in the first place? How do we prevent or mitigate this? https://arstechnica.com/information-technology/2019/11/scammers-try-a-new-way-to-steal-online-shoppers-payment-card-data/ Also, are there any 'hardening' or security tools out there for TB / PS 1.6? Ideally free (similar to Akeeba AdminTools for Joomla, etc) Mind sharing any TB hardening techniques? With the festive season coming up + what happened to this PS site and the Magento sites - understandably I'm a bit nervous (I'm sure I'm not the only one). So how do we protect our TB sites from these f**kers?
-
Hi guys I'm wondering if any of you have had experience with configuring TB + Panda + Litespeed module? If so, mind sharing the modifications you've had to make to make it work please?