<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: OpenCart CSRF Vulnerability</title>
	<atom:link href="http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/</link>
	<description>I swear this blog is different from the others!</description>
	<lastBuildDate>Thu, 01 Dec 2011 12:12:30 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Which shopping cart / ecommerce platform to choose? &#124; DEEP in PHP</title>
		<link>http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/comment-page-1/#comment-10261</link>
		<dc:creator>Which shopping cart / ecommerce platform to choose? &#124; DEEP in PHP</dc:creator>
		<pubDate>Thu, 03 Feb 2011 00:34:21 +0000</pubDate>
		<guid isPermaLink="false">http://blog.visionsource.org/?p=67#comment-10261</guid>
		<description>[...] OpenCart : security issues and not a great support from the main developer. See here and here. [...]</description>
		<content:encoded><![CDATA[<p>[...] OpenCart : security issues and not a great support from the main developer. See here and here. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A look inside a coder&#8217;s ego &#124; Zapotek&#039;s train of thought&#8230;</title>
		<link>http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/comment-page-1/#comment-6547</link>
		<dc:creator>A look inside a coder&#8217;s ego &#124; Zapotek&#039;s train of thought&#8230;</dc:creator>
		<pubDate>Wed, 08 Sep 2010 01:23:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.visionsource.org/?p=67#comment-6547</guid>
		<description>[...] asshole will reply like this. (These links prompted me to write this [...]</description>
		<content:encoded><![CDATA[<p>[...] asshole will reply like this. (These links prompted me to write this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Should We Use OpenCart? &#124; Made of Everything You&#39;re Not &#124; Eric Lamb</title>
		<link>http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/comment-page-1/#comment-5441</link>
		<dc:creator>Should We Use OpenCart? &#124; Made of Everything You&#39;re Not &#124; Eric Lamb</dc:creator>
		<pubDate>Tue, 25 May 2010 07:17:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.visionsource.org/?p=67#comment-5441</guid>
		<description>[...] another war going on between Daniel and a developer who found some pretty nasty CSRF issues. Again, Daniel showed his ass (along with a good helping of ignorance mixed with arrogance this time) with nothing being [...]</description>
		<content:encoded><![CDATA[<p>[...] another war going on between Daniel and a developer who found some pretty nasty CSRF issues. Again, Daniel showed his ass (along with a good helping of ignorance mixed with arrogance this time) with nothing being [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Coffee To Code &#187; Blog Archive &#187; Humble Helps</title>
		<link>http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/comment-page-1/#comment-5429</link>
		<dc:creator>Coffee To Code &#187; Blog Archive &#187; Humble Helps</dc:creator>
		<pubDate>Mon, 24 May 2010 06:43:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.visionsource.org/?p=67#comment-5429</guid>
		<description>[...] just ran across a post at PreachSecurity about a recent CSRF discovered in OpenCart, and a blog post by the discoverer about his interactions with the maintainer. I share Rafal&#8217;s (and Ben&#8217;s) frustration [...]</description>
		<content:encoded><![CDATA[<p>[...] just ran across a post at PreachSecurity about a recent CSRF discovered in OpenCart, and a blog post by the discoverer about his interactions with the maintainer. I share Rafal&#8217;s (and Ben&#8217;s) frustration [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Maynard</title>
		<link>http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/comment-page-1/#comment-4564</link>
		<dc:creator>Ben Maynard</dc:creator>
		<pubDate>Tue, 09 Feb 2010 03:02:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.visionsource.org/?p=67#comment-4564</guid>
		<description>Since this discussion is starting to turn ugly and nothing productive will come out of it, I have disabled comments on this article.</description>
		<content:encoded><![CDATA[<p>Since this discussion is starting to turn ugly and nothing productive will come out of it, I have disabled comments on this article.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yakiv</title>
		<link>http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/comment-page-1/#comment-4563</link>
		<dc:creator>Yakiv</dc:creator>
		<pubDate>Tue, 09 Feb 2010 01:47:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.visionsource.org/?p=67#comment-4563</guid>
		<description>@Harre Bellefon - Blogexecute is not my friend, number 1. As for the rest of what you said, you are making gross generalizations which are pathetic and have no substance. What is funny is that you were so compelled to respond to me here. Maybe you&#039;re one of the idiots I have ripped over there. Get a life.</description>
		<content:encoded><![CDATA[<p>@Harre Bellefon &#8211; Blogexecute is not my friend, number 1. As for the rest of what you said, you are making gross generalizations which are pathetic and have no substance. What is funny is that you were so compelled to respond to me here. Maybe you&#8217;re one of the idiots I have ripped over there. Get a life.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Maynard</title>
		<link>http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/comment-page-1/#comment-4562</link>
		<dc:creator>Ben Maynard</dc:creator>
		<pubDate>Mon, 08 Feb 2010 23:40:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.visionsource.org/?p=67#comment-4562</guid>
		<description>@Harre,

I have shared the source code, it is hosted on GitHub - http://github.com/bmaynard/OpenCart-Secured. You can download source/view all the changes I have made. If you mean share my changes with Daniel, then I offered to help fix the problem but he wasn&#039;t interested.</description>
		<content:encoded><![CDATA[<p>@Harre,</p>
<p>I have shared the source code, it is hosted on GitHub &#8211; <a href="http://github.com/bmaynard/OpenCart-Secured" rel="nofollow">http://github.com/bmaynard/OpenCart-Secured</a>. You can download source/view all the changes I have made. If you mean share my changes with Daniel, then I offered to help fix the problem but he wasn&#8217;t interested.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harre Bellefon</title>
		<link>http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/comment-page-1/#comment-4559</link>
		<dc:creator>Harre Bellefon</dc:creator>
		<pubDate>Mon, 08 Feb 2010 21:06:13 +0000</pubDate>
		<guid isPermaLink="false">http://blog.visionsource.org/?p=67#comment-4559</guid>
		<description>Well Yakiv, I&#039;m glad that you have found your way here, I hope that Ben will read on the OC forums what your main type of responce is when you don&#039;t get what you want. You are nothing but a little kid, screaming and shouting when it does not gets its candy. I&#039;m wondering when your friend Blogexecute will show up here.

@Ben, sorry your not sharing your code.</description>
		<content:encoded><![CDATA[<p>Well Yakiv, I&#8217;m glad that you have found your way here, I hope that Ben will read on the OC forums what your main type of responce is when you don&#8217;t get what you want. You are nothing but a little kid, screaming and shouting when it does not gets its candy. I&#8217;m wondering when your friend Blogexecute will show up here.</p>
<p>@Ben, sorry your not sharing your code.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Maynard</title>
		<link>http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/comment-page-1/#comment-4555</link>
		<dc:creator>Ben Maynard</dc:creator>
		<pubDate>Mon, 08 Feb 2010 16:46:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.visionsource.org/?p=67#comment-4555</guid>
		<description>@Harry,

I will be maintaining the forked version at the present time and will continue to support it for as long as possible. I have just posted on the thread that I saw with some information but I have offered to share the fix but the developer is not interested.

@Yakiv,

The only updates I will be doing to the fork is security updates and will not add new features/improve the project as I don&#039;t like 90% of the code. I wish to create my own e-commerce application but I have to try and find time to do this so will have to see how that goes.</description>
		<content:encoded><![CDATA[<p>@Harry,</p>
<p>I will be maintaining the forked version at the present time and will continue to support it for as long as possible. I have just posted on the thread that I saw with some information but I have offered to share the fix but the developer is not interested.</p>
<p>@Yakiv,</p>
<p>The only updates I will be doing to the fork is security updates and will not add new features/improve the project as I don&#8217;t like 90% of the code. I wish to create my own e-commerce application but I have to try and find time to do this so will have to see how that goes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yakiv</title>
		<link>http://blog.visionsource.org/2010/01/28/opencart-csrf-vulnerability/comment-page-1/#comment-4524</link>
		<dc:creator>Yakiv</dc:creator>
		<pubDate>Sat, 06 Feb 2010 20:10:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.visionsource.org/?p=67#comment-4524</guid>
		<description>@Ben, I was alerted to this post by another member of the forums on OpenCart.com. I will keep an eye on the thread. In general, I find Daniel to be very likable, so this blog post (with comments) is a bit surprising. However, his global moderators are allowed to act like arrogant jerks, delete posts without explanation, ban useful members, etc. The community there is horrible.  ...If you do truly fork OpenCart, I mean as a full-fledged open source project, please let me know. I do like OpenCart very much, but there are some basic flaws that prevent me from using it in production, namely the fact that there is no true modularity to the plugins. The process of installing and maintaining plugins and the core code base is down-right insane and I am not prepared to have regular migraines from using the software with customers.</description>
		<content:encoded><![CDATA[<p>@Ben, I was alerted to this post by another member of the forums on OpenCart.com. I will keep an eye on the thread. In general, I find Daniel to be very likable, so this blog post (with comments) is a bit surprising. However, his global moderators are allowed to act like arrogant jerks, delete posts without explanation, ban useful members, etc. The community there is horrible.  &#8230;If you do truly fork OpenCart, I mean as a full-fledged open source project, please let me know. I do like OpenCart very much, but there are some basic flaws that prevent me from using it in production, namely the fact that there is no true modularity to the plugins. The process of installing and maintaining plugins and the core code base is down-right insane and I am not prepared to have regular migraines from using the software with customers.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

