Apri
25

Magento / PayPal vulnerability advisory

Magento has a vulnerability (pre EE 1.10.1 or CE 1.5) on its PayPal integration, allowing an attacker to set the price of the payment and tricking Magento’s backend into thinking the whole normal price was paid. Patching is highly recommended.

Sept
27

Naxsi : Opensource Positive Model Application Firewall for NGINX

Hello Folks, Just a little note to announce that we released NAXSI, an Open Source, Positive Model Web Applicative Firewall for NGINX. Naxsi is now also an official OWASP project (yeepee !) Why ? Because, out there, first of all, there is not much open source WAFs, secondly, even if mod_security is awesome, we wanted [...]

Sept
22

Magento optimization Howto

Introduction With more than a thousand sites hosted, most of them being Magento shops, after leading R&D for 3 years in this field of performance optimization, this “Magento optimization howto” summarize most best practices. This said, most of points are also valid for other PHP based sites. Welcome to this Magento hardcore performance howto, I [...]

July
11

eBay acquires Magento : strategy analysis

  Ebay acquires Magento Since this official announce at the beginning of the week, e-commerce world is rustling with questions, fantasms, ideas on what this buyout means, the changes it will induce on Magento and the solution. These last 5 days, I have been swamped by e-mails asking my views on this change, as were [...]

Janu
13

NBS System becoming authorized France ARJEL certificator

NBS System, together with our partner INOVEN, is proud to announce the success in becoming an authorized France ARJEL certificator. The authorization has been published by ARJEL on December 2010 16th.