Login ID
Password
Find Login and Password
Home
About Us
Contact Us
Features
Full Feature List
E-commerce
Hosting Data Center
E-Bay Publishing
Security
Search Engine
Payment Processing
Content Management
Copy Protection
Graphic Design
Why Choose WebsiteForge
Portfolio
Website Design Portfolio
Flash Animation
Logo Design
Blog
Recent Upgrades
Forum
Support
FAQ
Prices
E-commerce Website Pricing
Informational Website Pricing
Testimonials

  

 

November 20th, 2008 at 8:09 am

Hello Website Forge community.

 

I received the following email from UPS:

 

-------

 

UPS OnLine® Tools Upgrade Notification

You are receiving this communication to notify you of changes that could affect your UPS OnLine Tools beginning March 1, 2009. Action may be required to ensure that the change does not adversely impact your business and use of the tools.

On March 1, 2009, UPS is moving from unchained to chained Digital Certificates to improve security when using the Internet. The change requires your system to support the Secured Socket Layer (SSL) Version 3.0 to be compatible with the new Digital Certificates.

It is highly recommended that you validate your configuration and upgrade your digital certificate to avoid connection breaks to your UPS OnLine Tools application. ........

 

-----------

 

After talking to our development team I was told that this should not affect Website Forge in any way. 

 

This email is for the customers that generally email us to ask this very question.

 

Thanks and have a great holiday sales season!

 

Shane Merem

Website Forge

www.websiteforge.com

web site design and ecommerce

 

 

 

Posted in
by
Views:
122
November 6th, 2008 at 3:42 pm

As some of you may already be aware, Websiteforge has been audited lately for PCI compliance. The following is a list of issues and the results of our findings. Please review this when you receive test results about your site. As always, feel free to submit your test results to support@websiteforge.com so we can review them for you and advise.

 

REVIEW:

OpenSSH Duplicate Block Denial
of Service Vulnerability

A version of OpenSSH prior to 4.4 is running on this host. This version
is affected by a Denial of Service vulnerability. However, an attack can
only be performed if version 1 of the SSH protocol is enabled.
Note: Vulnerabilities which result only in denial of service do not affect
PCI compliance; however, they may still be critical to your systems.
Service: SSH-2.0-OpenSSH_3.9p1
CVE: CVE-2006-4924
NVD: CVE-2006-4924
Bugtraq: 20216
CERT: 787448
CVSSv2: AV:N/AC:L/Au:N/C:N/I:N/A:C (Base Score:7.80)

 

FALSE ALERT. We do not have and never had SSHv1 enabled.

 
ProFTPD Command Truncation
Cross-Site Request Forgery
Vulnerability

The version of ProFTPD running on the remote host splits an overly
long FTP command into a series of shorter ones and executes each in
turn. If an attacker can trick a ProFTPD administrator into accessing a
specially-formatted HTML link, he may be able to cause arbitrary FTP
commands to be executed in the context of the affected application
with the administrator's privileges.
Service: 220 WebsiteForge FTP Server (www.websiteforge.com) ready
CVE: CVE-2008-4242
NVD: CVE-2008-4242
Bugtraq: 31289
Reference: http://bugs.proftpd.org/show_bug.cgi?id=3115
CVSSv2: AV:N/AC:H/Au:N/C:P/I:P/A:P (Base Score:5.10)
 

Valid alert. Software upgraded and patched, issue resolved.

 

OpenSSH X11 Session Hijacking
Vulnerability

OpenSSH is prone to a vulnerability that allows local attackers
to hijack forwarded X connections. The system must have both
IPv4 and IPv6 enabled at the same time for this to be exploited.
Successfully exploiting this issue may allow an attacker run arbitrary
shell commands with the privileges of the user running the affected
application. This issue is known to affect OpenSSH 4.3p2, though
other versions may also be affected. This vulnerability will trigger on
any SSH banner version prior to 'openssh-5'. OpenSSH packages
shipped with Red Hat Enterprise Linux 4 and 5 are not vulnerable to
this issue. However, Red Hat Enterprise Linux 2.1 and 3 are affected.
Service: SSH-2.0-OpenSSH_3.9p1
CVE: CVE-2008-1483
NVD: CVE-2008-1483
Bugtraq: 28444
CVSSv2: AV:L/AC:H/Au:S/C:C/I:C/A:C (Base Score:6.00)
 

FALSE ALERT. Our systems have IPv6 disabled and therefore are not affected.

 

Multiple Vulnerabilities in lighttpd
Prior to 1.4.20

The version of lighttpd running on this host is prone to multiple
vulnerabilities. These include a failure to properly sanitize user input
which could lead to information disclosure, a memory leak when
processing multiple headers that could lead to denial of service
conditions, and the ability to circumvent URL rewrite and redirect
patterns using encoding. Refer to the included references for more
information.
Service: lighttpd/1.4.18
CVE: CVE-2008-1531, CVE-2008-4298, CVE-2008-4359,
CVE-2008-4360
NVD: CVE-2008-1531, CVE-2008-4298, CVE-2008-4359,
CVE-2008-4360
Bugtraq: 28489, 31434, 31599, 31600
Reference: http://trac.lighttpd.net/trac/ticket/285Reference: http://
trac.lighttpd.net/trac/ticket/1720Reference: http://trac.lighttpd.net/trac/
ticket/1589Reference: http://trac.lighttpd.net/trac/ticket/1774
CVSSv2: AV:N/AC:L/Au:N/C:N/I:N/A:P (Base Score:5.00)
 

Valid alert. Removed the software because it was installed for a customer who has left and never used it.

Posted in
by
Views:
391
October 20th, 2008 at 1:18 pm

Here are the latest updates to the Website Forge core system:

 

- Froogle (google base) attributes are automatically mapped to fields on the Froogle Export form to reduce customer errors.
- Image Lists can show out-of-stock overlays.
-  Default distance for zip distance search can be specified.
-  Tree options performance optimizations - thousands of items should not be a problem to display in a tree.

- DHL realtime rating option.
- Zero-downtime publishing - the old version of the site will be 100% accessible during the publishing process, until the moment new published version is ready.
- Stricter validation of discount coupons.
- Detection of different error conditions in file uploader.
- File uploaders validates file types (won't allow to upload WMV when FLV is expected, etc).

Thanks, Shane Merem

www.websiteforge.com

Web Design and E-commerce

Posted in
by
Views:
190
October 7th, 2008 at 9:51 am

Hello everyone.  Here are a few upgrades added last Sunday:

 

1) Custom Date / Custom Number options for products now available

2) Custom Weight option added
3) URL fields in the layout builder can be set up to open in same window/new window/popup.
4) Instant unsubscribe links for blog and membership.
5) Ability to quickly unsubscribe a member from blog categories (all or some) on Edit Member form.
6) Image / Image List fields and option images display a hand cursor if they are clickable to help people see they can click the image.

 

REMINDER! Make sure your site is indexed properly by Google and Yahoo!

 

Don't forget how valuable it is to configure your web site for Google Sitemaps!  It is a built in feature of Website Forge to provide important page and product informationto Google!  Contact support so that we can help you with this feature.

 

Shane Merem

www.websiteforge.com

Web Site Design and E-commerce

Posted in
by
Views:
254
September 12th, 2008 at 5:09 pm

Can't seem to ever clear out your email inbox???

 

I get well over a hundred emails a day (not including spam).  Probably closer to 200.  Like me .. I know many of you struggle to get everything done -- but your inbox always seems to have unhandled email...

 

Do you ever feel like you can never get the CURRENT things in your INBOX done because you are always getting NEW email?

 

If so, I have the answer.....

 

***** Work  on your email from both ends! *****

 

FIRST:  Clear out the easiest NEW emails for a half hour..

 

THEN:  Sort your email showing oldest first!  (usually by clicking the date column) and then work from the bottom for a 1/2 hour.

 

Rinse.. Repeat.. (Just kidding)

 

It works really well for me.  This method will assure you don't neglect items in your inbox that require more "time" or "thought" because you are always flooded with brand new email messages.

 

I hope you find this tip useful!

 

Have a great weekend!

 

Shane Merem

www.websiteforge.com

www.magnusoft.com

Web Design and E-commerce Development

Posted in
by
Views:
357
September 8th, 2008 at 4:12 pm

Brian Shockley at "Shop Baker's Nook" has worked very hard the last couple years to create a web site from scratch with the help of Website Forge and turned it into an extremely successful endeavor. 

 

Beyond that he has:

 

-  Provided advice and support to other clients in our forum at www.websiteforge.com/forum/ to help others succeed

 

-  Improved his brick and mortar business

 

-  Provided great feedback from his web site customers so we can continue to improve Website Forge and offer the best possible upgrades

 

- And more...

 

Here is the latest email I received from Brian:


 

Hello.

 

Baker’s Nook LLC located in Saline Mi USA had a very nice article written about us by the examiner.com. This is a highly visited and trusted news site. You can read the article here: http://www.examiner.com/x-651-Southeast-MI-Home--Living-Examiner~y2008m8d29-Could-life-be-any-sweeter

 

This is a great time for our company. Sales are going through the roof and we are expanding in this new economy of ours.  Our website now generates over 100,000 visitors a month and we are becoming a leading authority in the cake decorating field.

 

This just shows what hard work and deploying the correct marketing effort can do for a company even in the so called down times.

 

Brian Shockley

CEO

ShopBakersNook.com

 

Thank you

www.ShopBakersNook.com

 

Thanks for the update Brian!  We all wish you continued success and appreciate your contributions.

 

Shane Merem

www.websiteforge.com

Web Design and E-Commerce

 

Posted in
by
Views:
349
September 5th, 2008 at 1:53 pm
Following are upgrades performed :
 
1) Users can use Java uploader in their image store. When the "Upload Files" button is clicked, the link in the top right corner of the window can be used to switch to the java mode. The system remembers last used upload mode.

2) Place Ad module supports using File Store for uploading files to fields of type File. On Frame Settings page of an Edit Item frame a file field can be set up to display a File Store selector instead of regular "Click here to upload" link. Previously this was only available for Image fields, now it can be changed for File fields too.

3) Member's File Upload notification can be turned on in Membership general settings.

4) Java uploader can be enabled for member ads on Ad module General Settings form. For it to work, image/file fields on the Edit Item page must be changed to Image/File Store (like in item 2).

5) On the Frame Settings page of a Search Box you can set some fields as "required". The search box will show a message and won't do any search until all required fields are specified.

6) In the Frame Settings of a Search Box you can set it to redirect to a details page when only one result is found.

7) "Required" setting is now supported for Product Options of types "Custom Price", "Custom File" and "Custom Text".

8) Zip Code search now displays nearest members first. Performance optimizations were applied to it.

9) Product Popularity now supports sorting by SKU and CSV export.
Posted in
by
Views:
358
August 6th, 2008 at 8:09 am

After 13 months of hard work and a crash course in internet fraud ... Kevin O'Brien at www.diveprodivegear.com sent me great this message yesterday.

 

This message is encouragement for the entire Website Forge community.  Your hard work combined with the power of Website Forge will equal business success. 

 

 

Shane:

 

Thought you'd also like to hear about our progress.

 

In the 13 months (June 2007) since we launched our website, www.diveprodivegear.com, we have gone from $0 sales to hitting $20K+ sales in July.

 

I expect we'll have our first $30K month during the Christmas season. This is just from the website. We have no brick & mortar business.

 

Thanks to the entire WF team for helping us achieve !! -- KOB.

_________________
Kevin O'Brien
www.DiveProDiveGear.com
Toll free: 1-877-55-DIVER

 

Related Article:  See http://www.websiteforge.com/blog.html?m17:post=important-credit-card-fraud-information-website-forge-shane-merem about Kevin's crash course in credit card fraud.

Posted in
by
Views:
528
July 1st, 2008 at 10:50 am

Would you like to be able to avoid fraudulent charges and help warn others?

 

With the help and suggestions from Chuck at www.clrmarine.com (and others) we decided to put up a BLOG of fraudulent activity to help warn other Website Forge merchants of possible fraudulent activity.

 

We will also start posting some tips and advice to help identify and avoid fraudulent transactions.

 

Go to www.support.websiteforge.com and clock the FRAUDNET button on the menu.

 

I have protected the page with the following username and password:

 

user: fraud

pass: net

 

Please email any possible fraudulent activity to support@websiteforge.com and I'll post it to the blog so we can warn others.

 

Shane

Posted in
by
Views:
447
June 18th, 2008 at 11:18 am

After listening to you -- I delivered! 

 

I am a home body.  I don't travel unless absolutely neccessary...  I put my butt on a train and went to Chicago, IL to the Internet Retailer Conference & Exhibition.

 

 

 

Of course only the G & L boys showed up! (www.gandlclothing.com).  Everyone else stood me up -- I won't mention any names (Brian Shockley) but stood up nonetheless.

 

So I spent alot of time trying to take photos by myself!!  (spare the "shiny head" jokes -- I've heard them all)

 

 

Do you know how embarrassing it is to get caught taking a photo of yourself in the restroom??!!

 

 

So I thought the elevator would work out better!  But of course the door flew open just as I was clicking the photo...  Needless to say the lady took the next elevator.  Pathetic.

 

Enter the G&L guys!  Finally someone to hang with at this amazing sushi bar.  Lots to eat and drink. 

 

 

After the lady took 4 photos of our plates -- she finally was able to fire off a photo of us. (I'm mumbling "Just hit the damn button lady..." while trying to hold a smile)

 

 

YES!  There was SAKE involved!  Or is that Saki?  Or Socky?  I'm too lazy to spell check.  Just suffice to say international booze was involved.

 

The G&L guys had to jet.. So I was back on my own again..  Found someone to take a photo..

 

 

Made up my mind that people from Chicago just can't operate a camera so ... Back to the drawing board...  Taking my own photos. 

 

 

Shopping (no not for purses!  It was the nearest mirror)

 

 

Orvis!  Finally get to see all that cool stuff up close.  Boy I wish I fished.

 

 

Checking out of the Hotel...

 

 

Wandering around Chicago picking up gifts for the family.  (Found a traveler that knew how to work a camera.  Thank goodness)

 

 

And the end.  Just remember... I was there and you weren't (Brian Shockley)

 

I enjoyed myself overall.  I also hooked up with the FiftyOne www.fiftyone.com guys and talked shop.  It was a good trip.

 

 

Shane Merem

www.websiteforge.com

Web design and e-commerce

 

Posted in
by
Views:
609
< Prev [1] 2 3 ... 12 13 14 Next >
     
 
Subscribers sign up here
Email
Password
Archives
November  2008
October  2008
September  2008
August  2008
July  2008
June  2008
May  2008
April  2008
March  2008
January  2008
December  2007
November  2007
October  2007
August  2007
July  2007
June  2007
May  2007
April  2007
March  2007
February  2007
January  2007
December  2006
January  2006
August  2005
March  2005
February  2005
January  2005
December  2004

 

 

 Website Feature List  Search Engine Marketing  Website Graphic Design   Website Forge FAQ's
 E-commerce  Payment Processing  Website Design      Website Prices
 Hosting Data Center  Content Management  Custom Website Design  Testimonials
 E-Bay Publishing  Copy Protection  Flash Website Design   Contact Us
 Security  Website Design Portfolio

 E-commerce Website

   Proposal Packages

 Informational Website

   Proposal Packages

       

Website Designed and Maintained With the Website Forge Website Design Solution!
Powered by www.websiteforge.com