Community Support Forums — WordPress® ( Users Helping Users ) — 2010-08-25T00:27:21-05:00 http://www.primothemes.com/forums/feed.php?f=4&t=601 2010-08-25T00:27:21-05:00 http://www.primothemes.com/forums/viewtopic.php?t=601&p=2567#p2567 <![CDATA[Re: Serious Problem with Subscriptions]]> Another quick tip.

If you're in the development phase, and you want to completely LOCK DOWN registrations, even with paid access, you can add this line to the functions.php file for your WordPress® theme.
Code:
add_filter("ws_plugin__s2member_check_register_access", "__return_false");

If you're running s2Member on a Multisite Blog Farm, you'll also need this snippet:
Code:
add_filter("ws_plugin__s2member_check_mms_register_access", "mms_lock_down");
function mms_lock_down(){ return "none"; }

Statistics: Posted by Jason Caldwell — August 25th, 2010, 12:27 am


]]>
2010-08-25T00:21:13-05:00 http://www.primothemes.com/forums/viewtopic.php?t=601&p=2566#p2566 <![CDATA[Re: Serious Problem with Subscriptions]]>

How in the world did these 2 people subscribe?

I just took a look at the log files you sent over. Your logs indicate a PayPal® transaction took place. So even though you've got Open Registration turned off, s2Member will always allow registration to a paying Customer. This is the intended behavior.

So the question is, how did someone in the public, formulate a link to PayPal, that would be pre-configured for s2Member, and subsequently, return them back to your site with registration access? And further, why would a hacker pay you? The answer to this, is almost always " you have a Button Code on your site somewhere ", or you published a Button Code inadvertently at one point or another. Even if this PayPal Button was deleted from your site, it's still possible for it to exist somewhere else on the web, where your content may have been syndicated by other services online.


Is it possible for them to subscribe by going directly to PayPal and passing the website altogether

Yes, anything is technically *possible*, although HIGHLY unlikely. The only way to avoid going through a Button that you generated, is if a Customer was smart enough to pre-configure their own Button Code with all of the proper return URLs, the `custom` value matching your domain, the proper `item_number` field, etc. Even then, the ONLY way a Customer would gain access after a successful transaction, is if s2Member communicates with PayPal and verifies through a direct connection, that the purchase being submitted to your WordPress installation is genuine ( i.e. VERIFIED by PayPal ).

On this same topic, there is an additional form of security that you can implement ( optional, but recommended ), where you can configure your PayPal account to reject ALL Button Codes that are unencrypted. Using PayPal's interface, you can create Button Codes that are encrypted by PayPal, and if you configure your PayPal account correctly, PayPal will reject any incoming Button Code that is UN-encrypted. s2Member does NOT natively support this in it's Button Generator ( yet )... however, this is coming very soon, it's on our @TODO list, but currently under review, due to some technical limitations.

Until then, you can use PayPal's Button Generator to secure your Buttons, or upgrade to s2Member Pro. This is not an issue at all with s2Member Pro, which implements PayPal® Pro Integration.
Video demo: [ viewtopic.php?f=4&t=304 ]

You can learn more about this security tip @ PayPal
https://cms.paypal.com/us/cgi-bin/?cmd= ... ebpayments
( this prevents hackers from changing prices, terms, etc. in your Button Code )

Statistics: Posted by Jason Caldwell — August 25th, 2010, 12:21 am


]]>
2010-08-22T14:25:16-05:00 http://www.primothemes.com/forums/viewtopic.php?t=601&p=2516#p2516 <![CDATA[Serious Problem with Subscriptions]]>
How in the world did these 2 people subscribe?

My website has 400 users and I use an Android application and the WP API to subscribe users. I have emailed these 2 users and asked them how they subscribed but have not gotten an answer back from them. The second one just happened this morning so I am hoping that I will get an answer from that person.

My concern is that these 2 users might be subscribing to get into my website to look for vulnerabilities. May be I'm being a little bit paranoid, but I need to find the answer to this question... Is it possible for them to subscribe by going directly to PayPal and passing the website altogether?

I really need help getting to the bottom of this.

thanks
Nick

Statistics: Posted by NickFox — August 22nd, 2010, 2:25 pm


]]>