iEntry 10th Anniversary Forum Rules Search
WebProWorld
Register FAQ Calendar Mark Forums Read
eCommerce Discussion Forum Ask questions about web hosting, merchant services and ecommerce issues. Topics include shopping carts, security, payment strategies, storefront partnerships, etc.

Share Thread: & Tags

Share Thread:

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-18-2008, 10:08 PM
ajpaulus65's Avatar
WebProWorld New Member
 
Join Date: Sep 2007
Posts: 16
ajpaulus65 RepRank 0
Default Ecommerce shows unsecured items

Hi All

I have an ecommerce store with Network Solutions and something on the website shows an unsecured item when they go to the shopping cart. I checked all links and they are all secured links. Can anyone help me find the problem since Network Solutions are stumped as well? Go to http://www.gymsupply.com and place something in the cart and then you'll get a message when you check out. What is it? Help!!!


Thanks for your time,
AJ
Reply With Quote
  #2 (permalink)  
Old 11-19-2008, 07:16 AM
WebProWorld Veteran
 
Join Date: Jan 2008
Posts: 466
amxfan RepRank 2amxfan RepRank 2
Default Re: Ecommerce shows unsecured items

Do you mean this?

"Added !Poster, Shawn Johnson Olympic Champion Poster (Qty: 1) to your cart"

Some carts show messages like this due to an exploit that was fixed by adding inventory control to the cart. The exploit allowed people to change the price and quantity of the item before checking out. To stay in PCI compliance some carts had to do this. This is the ONLY message I saw so I'm thinking you mean this one. I did not know NWS had to do this but I do know some others did.

Now you mention Network Solutions. I'm pulling my one site from them due to their shared hosting is NOT PCI compliant. When I signed up with them they told me it was. When I found out that it is not "through a PCI scan" I called sales and talked to 3 different sales people "called 3 times" and all 3 told me that yes shared hosting would meet my needs and yes it is PCI compliant. I called Tech support and they told me no it is not and cannot ever be due to the setup of their servers. I have been with NWS for over a year and they agreed to give me a full refund due to their sales people telling me a lie. I'm am now in the process of moving my site from them. I'm not sure if you're on a shared hosting plan with them or on their e-commerce plan so I thought I would give you a heads up.
Reply With Quote
  #3 (permalink)  
Old 11-19-2008, 09:19 AM
ajpaulus65's Avatar
WebProWorld New Member
 
Join Date: Sep 2007
Posts: 16
ajpaulus65 RepRank 0
Default Re: Ecommerce shows unsecured items

No, the message prompts the viewer that there is an unsecured item on the page and if they want to continue. Depending on what browser you are using, but with firefox, it just gives me a red line over the padlock in the right bottom corner and with others, it prompts them with a message box. Thanks for looking.
Reply With Quote
  #4 (permalink)  
Old 11-19-2008, 09:24 AM
wige's Avatar
Moderator
WebProWorld Moderator
 
Join Date: Jun 2006
Location: United States
Posts: 2,376
wige RepRank 5wige RepRank 5wige RepRank 5wige RepRank 5wige RepRank 5wige RepRank 5
Default Re: Ecommerce shows unsecured items

The following dependencies are not secured on the checkout page:

http://www.gymsupply.com/custompages...r/spacer10.gif
http://www.insidegymnastics.com/cont...n&sd=y&ulist=y
__________________
The best way to learn anything, is to question everything.
Interestingly Average Security Blog
Reply With Quote
  #5 (permalink)  
Old 11-19-2008, 09:39 AM
WebProWorld Veteran
 
Join Date: Jun 2004
Location: Indiana
Posts: 589
google junky RepRank 1
Default Re: Ecommerce shows unsecured items

I want to kind of reiterate what "wige" said.
Anything found in the format of an http in an https page will result in a page stating it has unsecure items in it.
There isn't any option but to fix it also.

This is the list of unsecure items from the page I was on:
# http://www.gymsupply.blogspot.com/
# http://www.gymsupply.com/index.asp?PageAction=CARTDETAILS&Page=1
# http://www.insidegymnastics.com/content/show/?a=426&z=1
# http://www.insidegymnastics.com/content/show/?a=430&z=1
# http://www.insidegymnastics.com/content/show/?a=431&z=1
# http://www.insidegymnastics.com/content/show/?a=432&z=1
# http://www.insidegymnastics.com/content/show/?a=433&z=1
# http://www.kipclub.com/


Good Luck,
Google Junky

Last edited by google junky; 11-19-2008 at 09:43 AM.
Reply With Quote
  #6 (permalink)  
Old 11-19-2008, 12:07 PM
ajpaulus65's Avatar
WebProWorld New Member
 
Join Date: Sep 2007
Posts: 16
ajpaulus65 RepRank 0
Default Re: Ecommerce shows unsecured items

Okay, I think I fixed it, but my boss said it still shows on his browser. Can you test for me again?
Reply With Quote
  #7 (permalink)  
Old 11-19-2008, 01:13 PM
WebProWorld Veteran
 
Join Date: Jun 2004
Location: Indiana
Posts: 589
google junky RepRank 1
Default Re: Ecommerce shows unsecured items

I checked in IE and Firefox and it looks to be good now.
Congrats!
Reply With Quote
  #8 (permalink)  
Old 11-19-2008, 01:33 PM
ajpaulus65's Avatar
WebProWorld New Member
 
Join Date: Sep 2007
Posts: 16
ajpaulus65 RepRank 0
Default Re: Ecommerce shows unsecured items

In IE, it states that there is a 'done, but with errors on page'.....should I be concerned with this message?
Reply With Quote
  #9 (permalink)  
Old 11-19-2008, 01:55 PM
WebProWorld Veteran
 
Join Date: Jun 2004
Location: Indiana
Posts: 589
google junky RepRank 1
Default Re: Ecommerce shows unsecured items

They are script/code errors. No need to worry about it. It is rare to find a page that IE wouldn't complain about. It poses no security problem.
You can fix them if you like by checking at W3C for validation.

Last edited by google junky; 11-19-2008 at 01:57 PM.
Reply With Quote
  #10 (permalink)  
Old 11-19-2008, 03:00 PM
Dubbya's Avatar
WebProWorld 1,000+ Club
WebProWorld MVP
 
Join Date: Nov 2006
Location: Steinbach, Manitoba, Canada
Posts: 1,898
Dubbya RepRank 4Dubbya RepRank 4Dubbya RepRank 4Dubbya RepRank 4Dubbya RepRank 4
Default Re: Ecommerce shows unsecured items

The "done but with errors on the page" indicates a JavaScript error.

If you view the page source in your browser, you'll find a Javascript error on line 12, right where your Google Urchin code is.

You're using the old version of Google's analytics tracking code.

Here's the new code for a ecommerce site:
Code:
<script type="text/javascript">
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
</script>
<script type="text/javascript">
var pageTracker = _gat._getTracker("UA-xxxxxx-x");
pageTracker._trackPageview();
</script>
More troubleshooting and installation information here:
old code:
How can I confirm that I've entered the tracking code correctly on my pages? - Google Analytics Help Center

New code:
How can I confirm that I've entered the tracking code correctly on my pages? - Google Analytics Help Center
Reply With Quote
  #11 (permalink)  
Old 11-19-2008, 05:48 PM
WebProWorld Veteran
 
Join Date: Apr 2004
Posts: 362
imvain2 RepRank 0
Default Re: Ecommerce shows unsecured items

Quote:
Originally Posted by google junky View Post
I want to kind of reiterate what "wige" said.
Anything found in the format of an http in an https page will result in a page stating it has unsecure items in it.
There isn't any option but to fix it also.

This is the list of unsecure items from the page I was on:
# All Things Gymnastics
# Gymnastics Grips, Gymnastics Mats, Gymnastics Equipment, Gymnastics Apparel- DGS 9.9 - Gymsupply.com
# News | Inside Gymnastics Magazine
# News | Inside Gymnastics Magazine
# News | Inside Gymnastics Magazine
# News | Inside Gymnastics Magazine
# News | Inside Gymnastics Magazine
# Kip Club - DGS 9.9's Affiliate Program


Good Luck,
Google Junky

I just want to clarify to everyone, this isn't exactly true.

Images, scripts, flash, style sheets, yes they have to be pulled through the digital certificate if on the secure page.

However, links do not need to point to a secure area. Like for example, a link to a home page doesn't need to be pushed through the digital certificate.
Reply With Quote
  #12 (permalink)  
Old 11-19-2008, 06:14 PM
WebProWorld Member
 
Join Date: Sep 2006
Posts: 59
puamana RepRank 0
Default Re: Ecommerce shows unsecured items

It simply means that EVERYTHING on the page must be called using a secure server link.

Some carts will allow relative links (.../.../file.txt) but you may need to go through and
change ALL links in the code to secure, and place copies of all images and dependent templates
in a secure directory (depending on how your server is configured).

For example, if you are calling a 'footer template' from your unsecure area of the site,
it would be flagged by the server as an 'unsecure' item on the page. Usually the script
running the cart has secure/unsecure access, as long as you specify in your settings you are
running a secure cart and provide the secure url to the cart.

- Puamana
Reply With Quote
  #13 (permalink)  
Old 11-19-2008, 06:53 PM
WebProWorld Veteran
 
Join Date: Apr 2004
Posts: 362
imvain2 RepRank 0
Default Re: Ecommerce shows unsecured items

Quote:
Originally Posted by puamana View Post
It simply means that EVERYTHING on the page must be called using a secure server link.

Some carts will allow relative links (.../.../file.txt) but you may need to go through and
change ALL links in the code to secure, and place copies of all images and dependent templates
in a secure directory (depending on how your server is configured).

For example, if you are calling a 'footer template' from your unsecure area of the site,
it would be flagged by the server as an 'unsecure' item on the page. Usually the script
running the cart has secure/unsecure access, as long as you specify in your settings you are
running a secure cart and provide the secure url to the cart.

- Puamana
No, NOT everything. For example, a link to the HOME page doesn't need to be pointed to the page in the digital certificate.

Visit 99% of the ecommerce websites and get into the secure environment and the links to the other pages will be unsecure, yet no errors will pop up. Why? because only items that are "included" need to be secure, like images, external script files, css files and flash files.
Reply With Quote
  #14 (permalink)  
Old 11-19-2008, 06:54 PM
WebProWorld Member
 
Join Date: Nov 2003
Location: Las Vegas, NV -- USA
Posts: 88
Shift4SMS RepRank 0
Default Re: Ecommerce shows unsecured items

Quote:
Originally Posted by google junky View Post
They are script/code errors. No need to worry about it. It is rare to find a page that IE wouldn't complain about. It poses no security problem.
You can fix them if you like by checking at W3C for validation.
I have to STRONGLY disagree here. If IE displays a script error then you have the show scripting errors turned on and it has detected a real script error. Dubbya already pointed out the error. I have it turned on because I do a lot of JS coding. Because I have it turned on, I see these annoying warnings on many sites. For me it throws up a red flag because it indicates sloppy coding: Do I trust this site when they are publishing syntactically incorrect javascript? How confident am I that the server side code is coded any better?

My recommendation is that when you test for IE compatibility, turn on "show script errors" and make sure you don't have any.
__________________
Steve Sommers (blog)
Shift4 Corporation

Creators of $$$ ON THE NET(tm) Payment Processing Services
Reply With Quote
  #15 (permalink)  
Old 11-19-2008, 07:36 PM
villageloop's Avatar
WebProWorld Member
 
Join Date: Dec 2007
Location: South Florida
Posts: 67
villageloop RepRank 1
Default Re: Ecommerce shows unsecured items

Quote:
Originally Posted by Shift4SMS View Post
I have to STRONGLY disagree here. If IE displays a script error then you have the show scripting errors turned on and it has detected a real script error. Dubbya already pointed out the error. I have it turned on because I do a lot of JS coding. Because I have it turned on, I see these annoying warnings on many sites. For me it throws up a red flag because it indicates sloppy coding: Do I trust this site when they are publishing syntactically incorrect javascript? How confident am I that the server side code is coded any better?

My recommendation is that when you test for IE compatibility, turn on "show script errors" and make sure you don't have any.
I would have to agree with Shift4SMS here.
Find your errors and fix them.
Even if it is not a critical error, it is still an error and would reduce your credibility as a developer in the same way a broken image on your site reduces your credibility as a designer.
Reply With Quote
  #16 (permalink)  
Old 11-28-2008, 07:24 AM
WebProWorld New Member
 
Join Date: Nov 2008
Posts: 1
d.vincent RepRank 0
Default Re: Ecommerce shows unsecured items

I am doing my internship at the company Cashtronics and they are used to dealing with security problems on websites. I am sure they can help you out.
you can find the contact on La Solution de paiement en ligne sécurisé par CASHTRONICS
Reply With Quote
  #17 (permalink)  
Old 01-01-2009, 03:47 AM
WebProWorld Member
 
Join Date: Dec 2007
Posts: 72
pixma85 RepRank 0
Default Re: Ecommerce shows unsecured items

make sure the links have /productabc.html instead of www.website.com/productabc.html
Reply With Quote
Reply

  WebProWorld > eCommerce > eCommerce Discussion Forum

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
selling items I do not have Tubby Marketing Strategies Discussion Forum 14 02-17-2008 03:51 AM
Alt Tags on Non-descript items scot184 Search Engine Optimization Forum 8 03-06-2006 08:47 AM
Ethical question relating to unsecured forms... danlefree Internet Security Discussion Forum 2 06-24-2005 03:11 PM
America One Funding - Unsecured Loans - $5 to $3000 per lead mthomas Affiliate Marketing Discussion Forum 2 10-08-2004 06:07 PM


All times are GMT -4. The time now is 11:35 AM.



Search Engine Optimization by vBSEO 3.3.0