Online shopping cart flaw makes for easy discounts

A flaw in a commonly used Australian e-commerce software package may allow shoppers to give themselves discounts on the products they purchase, according to an alert posted by Trust Factory BV, a security company based in the Netherlands.

The software, called ShopFactory, is produced by Pty. Ltd., a company based in Victoria, and is a development tool for creating e-commerce sites. Among other things, ShopFactory allows merchants to create online shopping carts to store items that visitors select for purchase.

The security hole concerns the way ShopFactory stores price information on the items that customers select in shopping carts, according to Richard van den Berg, a security architect at Trust Factory, located in The Hague.

As opposed to the e-commerce technology used by online vendors such as Inc.,'s software stores shopping cart information for return customers in an unencrypted form directly in the cookies stored on customer computers.

Van den Berg first noticed the problem at the Web site of a local sandwich shop in the Netherlands that used's software to enable customers to order sandwiches online.

With the Netherlands' transition to the Euro in January of 2001, van den Berg noticed that his typical sandwich order had become more expensive. The problem: Sandwiches were now paid for in Euros, but the prices on his order form at the shop's Web site were still set to Guilder, the currency used in the Netherlands prior to the Euro's introduction.

With item pricing information used by the ShopFactory software stored in cookies on the computers of customers, rather than on a central database owned and controlled by the sandwich shop, it was virtually impossible for the sandwich shop to update product prices on its own, van den Berg said.

"As soon as I looked at the cookie, I saw that all my lunches were there as well as the prices and realized that that's why they were having such a problem with the Euro switch over," van den Berg said.

Even worse for the sandwich shop, van den Berg discovered that the ShopFactory software accepted whatever price information was provided by the cookie, meaning that anyone with a text editor and knowledge about where to locate the cookie on their computer could adjust the price of the items they order and submit it to the online merchant, giving themselves a steep discount.

Designed for small online merchants, ShopFactory is meant to simplify the e-commerce Web site design process. The product contains built-in functions, wizards and "point-and-click commands" that require little or no software programming experience, according to information on's ShopFactory Web site.

Still, van den Berg says that the company's implementation of online shopping carts is unacceptable.

"I totally understand that it's a lightweight solution to push (data) to the client, but instead of storing prices, they could store the IDs of items in the cart and pull prices out of the store's own database. What ( has done is very lazy. They've implemented shopping carts in a way that is very simple and straightforward, but not secure, " van den Berg said.

No one at could be reached by telephone or e-mail.

According to van den Berg, Trust Factory contacted in early October regarding the problem.

After being informed of the problem, set up a test e-commerce site on which the cookie creation feature was disabled and asked Trust Factory to prove their exploit of the ShopFactory software.

The workaround proved easy to defeat, van den Berg said. Even with cookie creation turned off, the ShopFactory software would still accept information from cookies it found. By simply modifying a ShopFactory cookie from the sandwich shop to match the test site set up by, van den Berg was able to submit a discounted order for himself.

Following the unsuccessful test, Trust Factory worked through Chief Executive Officer Steffan Klein to resolve the problem, but never communicated directly with the ShopFactory technical team, according to van den Berg.

According to the Trust Factory alert, has issued an updated version of its Trust Factory software, version 5.8, that resolves the problem by disabling the ability of the software to read information from cookies when the cookie creation feature was disabled.

But that fix could create more headaches for the merchants that use ShopFactory, van den Berg said.

"They provided a fix for shops that are willing and able to not use cookies for returning customers. For my lunch site, though, that would mean I have to recreate my lunch order every time I visit," van den Berg said.

According to van den Berg, further communication between Trust Factory and broke down when the company failed to provide the fix to Trust Factory to test, and when Klein became vague about whether the fix had been released and ShopFactory customers notified of the problem.

Still, notifying customers might be a tall task. Links from's Web site to the "thousands of sites" that use ShopFactory reveals a long list of small shops and online merchants scattered across the globe and selling everything from cosmetics to wedding gifts to pets and "green living" products.

The Web site had no mention of the security problem Tuesday, and the support forum for both security and product upgrades were absent of any mention of Version 5.8 of ShopFactory.

Customers using ShopFactory on their Web sites are advised to upgrade to version 5.8 and to set the "Remember Shopping cart for (days)" field to zero on using the administrative interface of the product, effectively disabling that feature, according to Trust Factory.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Paul Roberts

IDG News Service
Show Comments


James Cook University - Master of Data Science Online Course

Learn more >


Victorinox Werks Professional Executive 17 Laptop Case

Learn more >



Back To Business Guide

Click for more ›

Brand Post

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?