• You MUST read the Babiato Rules before making your first post otherwise you may get permanent warning points or a permanent Ban.

    Our resources on Babiato Forum are CLEAN and SAFE. So you can use them for development and testing purposes. If your are on Windows and have an antivirus that alerts you about a possible infection: Know it's a false positive because all scripts are double checked by our experts. We advise you to add Babiato to trusted sites/sources or disable your antivirus momentarily while downloading a resource. "Enjoy your presence on Babiato"

Active eCommerce CMS By ActiveITzone 23471405

Active eCommerce CMS By ActiveITzone V8.7

No permission to download
I accessed their site during the weekend and suspected that the bugs in the code were purposely placed there to prompt a user to contact them for customization or update.

The demo admin and demo front-end looks so perfect with the add-ons. {I wish I was a php guy, would fix all this for free and in a short time. }
------
I dunno if any one has tried the add-ons here on v4.0? dID IT WORK?
 
  • Like
Reactions: wonraywildsparks
The backdoor that drops the database has been inserted into the routes. This opens a security vulnerability. If a malicious agent accesses that particular route in a store's system using Active eCommerce, even if the software was legitimate, it would trigger the behavior of the backdoor, erasing all data from the database.

I know a little about routes, but one that drops a whole database file. Wow, that's intense. Yes, that's not a good idea
Too bad!
In fact, the source code is on google search results. I wouldn't blame them.
----
But for business privacy, I don't support it. The backdoor shouldn't be accessible
 
  • Like
Reactions: wonraywildsparks
they delete the backdoor once its installed with valid license code . all u need to do (whoever saying purchased the script) install it will licese code in ur system , tell them that google keep suspending the site because it has some kinda social engineering script or backdoor . then they will login to ur hosting and delete the backdoor. i purchased it long time ago and i forgot the email and pass . :{
 
  • Wow
Reactions: Chijioke
they delete the backdoor once its installed with valid license code . all u need to do (whoever saying purchased the script) install it will licese code in ur system , tell them that google keep suspending the site because it has some kinda social engineering script or backdoor . then they will login to ur hosting and delete the backdoor. i purchased it long time ago and i forgot the email and pass . :{

then u can share the database and code here .
 
  • Like
Reactions: Chijioke
I see "this is a pirated copy of Active Ecommerce on the header" . Please how can one fix this?

Check your public/index.php file. Usually the backdoor replaces the PHP code with static content with this message. Just restore the public/index.php file, and everything should be back to normal.

I posted what I believe to be a fix for these backdoors. Take a look at my previous posts in this thread and you will find it. Just install as instructed and it should not happen again.
 
  • Like
Reactions: Chijioke
Check your public/index.php file. Usually the backdoor replaces the PHP code with static content with this message. Just restore the public/index.php file, and everything should be back to normal.

I posted what I believe to be a fix for these backdoors. Take a look at my previous posts in this thread and you will find it. Just install as instructed and it should not happen again.

THANK YOU, MATE


I HAVE A NEW CHALLENGE WITH THE MAINTENANCE MODE - CLICKED ON THE MAINTENANCE MODE SWITCH TO ACTIVATE IT, TRIED TO DEACTIVATE IT, SEVERAL TIMES BUT IT DIDNT REFLECT ON THE FRONT END AND ALSO THE SWITCH STILL REMAINED ACTIVE EVEN AFTER REFRESHING IT. STILL SHOWS IT. what should i do? Already changed it to 0 in business_settings, didn't work as well. PLEASE HELP
 

Attachments

  • Screenshot 2021-03-06 183841.png
    Screenshot 2021-03-06 183841.png
    40.1 KB · Views: 20
THANK YOU, MATE


I HAVE A NEW CHALLENGE WITH THE MAINTENANCE MODE - CLICKED ON THE MAINTENANCE MODE SWITCH TO ACTIVATE IT, TRIED TO DEACTIVATE IT, SEVERAL TIMES BUT IT DIDNT REFLECT ON THE FRONT END AND ALSO THE SWITCH STILL REMAINED ACTIVE EVEN AFTER REFRESHING IT. STILL SHOWS IT. what should i do? Already changed it to 0 in business_settings, didn't work as well. PLEASE HELP


try it with mysql .... variable :
SHOW VARIABLES LIKE 'sql_mode'; with this query SET GLOBAL sql_mode = 'NO_ENGINE_SUBSTITUTION';
(but you should have host right to do this )
it may work ... or else use the V3.9 settings on your cms
 
Last edited:
  • Like
Reactions: Chijioke
Look like v4.0 is not fully nulled. Its still have many callback that's why asking for verification after successfully install.
 
  • Like
Reactions: Montygarg910
THANK YOU, MATE


I HAVE A NEW CHALLENGE WITH THE MAINTENANCE MODE - CLICKED ON THE MAINTENANCE MODE SWITCH TO ACTIVATE IT, TRIED TO DEACTIVATE IT, SEVERAL TIMES BUT IT DIDNT REFLECT ON THE FRONT END AND ALSO THE SWITCH STILL REMAINED ACTIVE EVEN AFTER REFRESHING IT. STILL SHOWS IT. what should i do? Already changed it to 0 in business_settings, didn't work as well. PLEASE HELP
dead dont use more broooo then borrow your database
 
  • Like
Reactions: Chijioke
The scripts authors are using the new methods to protect their script from null. Now its challenge for all null masters here to update their null skills further to broke their protection.
The real nulling is not only bypass license protections but also to remove all callback so script author can't get info that where their scripts is working.
 
Last edited:
try it with mysql .... variable :
SHOW VARIABLES LIKE 'sql_mode'; with this query SET GLOBAL sql_mode = 'NO_ENGINE_SUBSTITUTION';
(but you should have host right to do this )
it may work ... or else use the V3.9 settings on your cms
Was unable to do the first option. Got this error
SET GLOBAL sql_mode = 'NO_ENGINE_SUBSTITUTION'



MySQL said: Documentation

#1227 - Access denied; you need (at least one of) the SUPER privilege(s) for this operation.

However, I fixed it by simply running a new installation and using the database I used in xampp development.
And also credentials, I copied the settings in the previous .env file and pasted it in the new one. And also product photos, I copied all of it from public/upload/all to the new corresponding file.

Hopes this solves someone's problem too
 
THANK YOU, MATE


I HAVE A NEW CHALLENGE WITH THE MAINTENANCE MODE - CLICKED ON THE MAINTENANCE MODE SWITCH TO ACTIVATE IT, TRIED TO DEACTIVATE IT, SEVERAL TIMES BUT IT DIDNT REFLECT ON THE FRONT END AND ALSO THE SWITCH STILL REMAINED ACTIVE EVEN AFTER REFRESHING IT. STILL SHOWS IT. what should i do? Already changed it to 0 in business_settings, didn't work as well. PLEASE HELP

Try php artisan up in console.

I fixed some bugs I found, added a custom page to work with the Wallet (Add or Remove credits from users), and I'm integrating MercadoPago (Payment Method from Argentina/Brazil). If anyone is interested, send a PM. I'll be glad to share.
 
  • Like
Reactions: Chijioke
Try php artisan up in console.

I fixed some bugs I found, added a custom page to work with the Wallet (Add or Remove credits from users), and I'm integrating MercadoPago (Payment Method from Argentina/Brazil). If anyone is interested, send a PM. I'll be glad to share.
wow please check inbox
 
AdBlock Detected

We get it, advertisements are annoying!

However in order to keep our huge array of resources free of charge we need to generate income from ads so to use the site you will need to turn off your adblocker.

If you'd like to have an ad free experience you can become a Babiato Lover by donating as little as $5 per month. Click on the Donate menu tab for more info.

I've Disabled AdBlock