Ecommerce software home
Shopping Cart Software Forum for Ecommerce Templates
 
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

Find us on Facebook Follow us on Twitter View our YouTube channel
Search our site
Forum Search
Google Site Search
 All Forums
 Technical
 PHP (Unix / Linux / Apache) versions
 Braintree SDK out of date - Site subject to attack
Author « Topic »  

homerads
Starting Member

United Kingdom
13 Posts

Posted - 01/04/2024 :  04:59:48  
Hi Vince/everyone,

We've recently been hit with some kind of exploit attack where we get 1000s of orders placed with random names, addresses and IPs.

Braintree have come back with various recommendations but their main point is regarding the SDK version used. From what I can see, the 'inccart.php' code still calls 3.14.0

They have suggested we need to update to a later version, at least 5.5.0 or higher. Can we simply change the call from the code to a later PHP library or is there a lot more variables to change?

For reference https://github.com/braintree/braintree_php/blob/master/CHANGELOG.md and https://developer.paypal.com/braintree/docs/reference/general/server-sdk-migration-guide/php

quote:
... it appears that the 3D Secure authentication was not completed successfully. This occurred because the Lookup was initiated before the Device Data was collected (error code 2270). To fix this, you'll basically need to (i) update your client to the latest version of our JS SDK and (ii) set the collectDeviceData option to true when calling verifyCard(). Starting from Braintree v3.94.0, this option facilitates additional device data collection, reducing lookup failures and authentication challenges for customers. Please refer to our recommended settings for specific information.


quote:
We recommend watching our SDKs on Github to stay informed about the latest versions and ensure you are using Braintree Web with the proper CSP directives.


Thanks for any help.

Vince
Administrator

42756 Posts

Posted - 01/07/2024 :  09:44:43  
Hi Homerads
I'm sorry to hear this is happening but really, we are not actually using the SDK at all, but just have the header set to that version number even though it doesn't affect anything. Do you want to maybe pass the recommendations on from Braintree to my email, (vince AT ecommercetemplates DOT com) and I'll take a look at what they are saying?

Vince

Click Here for Shopping Cart Software
Click Here to sign up for our newsletter
Click Here for the latest updater
  « Topic »  
Jump To:
Shopping Cart Software Forum for Ecommerce Templates © 2002-2022 ecommercetemplates.com
This page was generated in 0.03 seconds. Snitz Forums 2000