<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>SalesCart Forums : Security Settings Required?</title>
  <link>http://forum.salescart.com/forum/</link>
  <description><![CDATA[This is an XML content feed of; SalesCart Forums : SalesCart Standard / PRO / SQL : Security Settings Required?]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Sat, 11 Apr 2026 02:13:38 +0000</pubDate>
  <lastBuildDate>Tue, 06 Sep 2005 09:58:44 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 11.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>forum.salescart.com/forum/RSS_post_feed.asp?TID=410</WebWizForums:feedURL>
  <image>
   <title><![CDATA[SalesCart Forums]]></title>
   <url>http://forum.salescart.com/forum/forum_images/web_wiz_forums.png</url>
   <link>http://forum.salescart.com/forum/</link>
  </image>
  <item>
   <title><![CDATA[Security Settings Required? : ummm... you&amp;#039;re reiterating...]]></title>
   <link>http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1510&amp;title=security-settings-required#1510</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.salescart.com/forum/member_profile.asp?PF=4">Techno Geek</a><br /><strong>Subject:</strong> 410<br /><strong>Posted:</strong> September/06/05 at 9:58am<br /><br />ummm... you're reiterating what I've said in my replies. But yeah, IUSR (the only web account) needs those permissions.]]>
   </description>
   <pubDate>Tue, 06 Sep 2005 09:58:44 +0000</pubDate>
   <guid isPermaLink="true">http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1510&amp;title=security-settings-required#1510</guid>
  </item> 
  <item>
   <title><![CDATA[Security Settings Required? : Ok so does this mean that I should...]]></title>
   <link>http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1505&amp;title=security-settings-required#1505</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.salescart.com/forum/member_profile.asp?PF=35">Big Bear</a><br /><strong>Subject:</strong> 410<br /><strong>Posted:</strong> September/04/05 at 11:10pm<br /><br />Ok so does this mean that I should have..<br /><br /><strong>FPDB</strong>: READ/WRITE <br /><strong>ONLINE</strong>: READ/WRITE <br /><strong>IUSR</strong>: READ/WRITE permissions on the database with permissions setup to propagate to the child objects<br /><br />Or is this incorrect? <br />]]>
   </description>
   <pubDate>Sun, 04 Sep 2005 23:10:42 +0000</pubDate>
   <guid isPermaLink="true">http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1505&amp;title=security-settings-required#1505</guid>
  </item> 
  <item>
   <title><![CDATA[Security Settings Required? : When you setup permissions on...]]></title>
   <link>http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1495&amp;title=security-settings-required#1495</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.salescart.com/forum/member_profile.asp?PF=4">Techno Geek</a><br /><strong>Subject:</strong> 410<br /><strong>Posted:</strong> September/01/05 at 10:13am<br /><br />When you setup permissions on a directory, the child object will inherit the permissions as well. In some rare cases you will have to force the permissions to propagate.]]>
   </description>
   <pubDate>Thu, 01 Sep 2005 10:13:33 +0000</pubDate>
   <guid isPermaLink="true">http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1495&amp;title=security-settings-required#1495</guid>
  </item> 
  <item>
   <title><![CDATA[Security Settings Required? : What about this statement that...]]></title>
   <link>http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1489&amp;title=security-settings-required#1489</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.salescart.com/forum/member_profile.asp?PF=35">Big Bear</a><br /><strong>Subject:</strong> 410<br /><strong>Posted:</strong> August/31/05 at 4:11pm<br /><br />What about this statement that I located in the Knowledge base???<br /> <br />"<strong>The IUSR only needs READ/WRITE permissions on the database directory. The permissions should be setup to propagate to the child objects.</strong>"<br /><br />Should this also be set up this way?]]>
   </description>
   <pubDate>Wed, 31 Aug 2005 16:11:29 +0000</pubDate>
   <guid isPermaLink="true">http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1489&amp;title=security-settings-required#1489</guid>
  </item> 
  <item>
   <title><![CDATA[Security Settings Required? : FPDB: READ/WRITE ONLINE: READ/WRITE  That...]]></title>
   <link>http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1484&amp;title=security-settings-required#1484</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.salescart.com/forum/member_profile.asp?PF=4">Techno Geek</a><br /><strong>Subject:</strong> 410<br /><strong>Posted:</strong> August/31/05 at 8:39am<br /><br />FPDB: READ/WRITE<br />ONLINE: READ/WRITE<br /><br />That is it. Anything beyond the privileges above is not necessary.]]>
   </description>
   <pubDate>Wed, 31 Aug 2005 08:39:43 +0000</pubDate>
   <guid isPermaLink="true">http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1484&amp;title=security-settings-required#1484</guid>
  </item> 
  <item>
   <title><![CDATA[Security Settings Required? : Again, I apologize for my misscommunication. This...]]></title>
   <link>http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1480&amp;title=security-settings-required#1480</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.salescart.com/forum/member_profile.asp?PF=35">Big Bear</a><br /><strong>Subject:</strong> 410<br /><strong>Posted:</strong> August/30/05 at 11:54am<br /><br />Again, I apologize for my misscommunication.<br />This is a really simple request, please don't look into it further than necesasary.<br /><br />All I wish to know is what REAR WRITE priveleges need to be set up for the SALES CART FOLDERS.<br /><br />I got into this mess because some of the priveleges aparently gave the HACKER access to my web site so he could run a SCRIPT & change my index.htm page.<br /><br />In the mean time my host provider killed the READ WRITE priveledges which were set up on my site because they thought that they were too leanent & posed a SECURITY RISK.<br /><br />All I need to know is the RECOMENDED SALES CART READ WRITE Priveledges which will result in persons to be able to order items from my store.<br /><br />I only mentioned the version as SQL 5.0 because I thought that it might make a difference as to what READ WRITE priveledges are required.<br /><br />Big Bear ]]>
   </description>
   <pubDate>Tue, 30 Aug 2005 11:54:44 +0000</pubDate>
   <guid isPermaLink="true">http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1480&amp;title=security-settings-required#1480</guid>
  </item> 
  <item>
   <title><![CDATA[Security Settings Required? : Big Bear: You&amp;#039;re using SQL?...]]></title>
   <link>http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1479&amp;title=security-settings-required#1479</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.salescart.com/forum/member_profile.asp?PF=4">Techno Geek</a><br /><strong>Subject:</strong> 410<br /><strong>Posted:</strong> August/30/05 at 10:37am<br /><br />Big Bear: You're using SQL? If so, then the IUSR write privilages wouldn't necessarily apply to your site. The SQL database is hopefully hosted on a remote server and it should be behind a firewall at the very least. This is what your host would do for you. <br /><br />How did you setup your connection strings? Are you using DSN to connect to the SQL server?]]>
   </description>
   <pubDate>Tue, 30 Aug 2005 10:37:25 +0000</pubDate>
   <guid isPermaLink="true">http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1479&amp;title=security-settings-required#1479</guid>
  </item> 
  <item>
   <title><![CDATA[Security Settings Required? : I&amp;#039;m getting similar message...]]></title>
   <link>http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1478&amp;title=security-settings-required#1478</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.salescart.com/forum/member_profile.asp?PF=170">qrsystems</a><br /><strong>Subject:</strong> 410<br /><strong>Posted:</strong> August/30/05 at 8:13am<br /><br />I'm getting similar message on my email on daily bases. The hacker is doing different stuff with my site.<br /><br />sample of one of the emails is as shown below<br />Is there any one who can help us on this.<br /><br />"This is an automated response sent from SalesCart <br /><br />Security Error: Unable to open referring page. <br /><br />Order Number: 90 <br />Item Number: edrlcnfjzh@mydomain.com <br />Posted Price: edrlcnfjzh@mydomain.com <br />Actual Price: 0 <br /><br />Posting URL: http://www.mydomain.com/ <br />Browser: <br />Server: www.mydomanin.com "<br /><br />Thanks<br />Dave <img border="0" src="http://forum.salescart.com/forum/smileys/smiley2.gif" border="0"> ]]>
   </description>
   <pubDate>Tue, 30 Aug 2005 08:13:07 +0000</pubDate>
   <guid isPermaLink="true">http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1478&amp;title=security-settings-required#1478</guid>
  </item> 
  <item>
   <title><![CDATA[Security Settings Required? : Some of the security settings...]]></title>
   <link>http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1477&amp;title=security-settings-required#1477</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.salescart.com/forum/member_profile.asp?PF=35">Big Bear</a><br /><strong>Subject:</strong> 410<br /><strong>Posted:</strong> August/29/05 at 11:41pm<br /><br />Some of the security settings that I understand need to be set up are..<br /><br />The IUSR only needs READ/WRITE permissions on the database directory. The<br />permissions should be setup to propagate to the child objects.<br /><br />and<br /><br />Both the /fpdb and /online should have READ/WRITE permissions. The user<br />that should have this permission is the IUSR.<br /><br />Am I missing any other settings?<br /><br />Big Bear <br />]]>
   </description>
   <pubDate>Mon, 29 Aug 2005 23:41:48 +0000</pubDate>
   <guid isPermaLink="true">http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1477&amp;title=security-settings-required#1477</guid>
  </item> 
  <item>
   <title><![CDATA[Security Settings Required? : Perhaps I wasn&amp;#039;t clear enough,...]]></title>
   <link>http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1476&amp;title=security-settings-required#1476</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://forum.salescart.com/forum/member_profile.asp?PF=35">Big Bear</a><br /><strong>Subject:</strong> 410<br /><strong>Posted:</strong> August/29/05 at 8:06pm<br /><br />Perhaps I wasn't clear enough, that is my fault due to ignorance of the server permission requirements..<br />What I meant to ask is what are the server side permissions supposed to be set up as.<br />I know some stuff is supposed to be set up as Read Only & yet others get Write Privileges.<br />I hope this is clear enough as I am not very familiar with what is required for Sales Cart SQL to be set up properly on the server side.<br /><br />It seems I had a Global Write privilege set up.. I do not know why but I seem to remember it was required or Sales Cart SQL would not work properly. Anyway... this is how the Hacker got in. <br /><br />What I need to know now is what server side permission settings are required for Sales Cart SQL to function correctly & yet give me a secure web site.<br /><br />thanks,<br />Big Bear<br />]]>
   </description>
   <pubDate>Mon, 29 Aug 2005 20:06:08 +0000</pubDate>
   <guid isPermaLink="true">http://forum.salescart.com/forum/forum_posts.asp?TID=410&amp;PID=1476&amp;title=security-settings-required#1476</guid>
  </item> 
 </channel>
</rss>