<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Crafty Syntax Live Help Archives - Orange Internet Solutions</title>
	<atom:link href="https://orangeinternetsolutions.com/tag/crafty-syntax-live-help/feed/" rel="self" type="application/rss+xml" />
	<link>https://orangeinternetsolutions.com/tag/crafty-syntax-live-help/</link>
	<description>All You Need for Your Online Business</description>
	<lastBuildDate>Tue, 26 Aug 2014 17:31:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://orangeinternetsolutions.com/wp-content/uploads/2017/10/orange-favicon-1-75x75.png</url>
	<title>Crafty Syntax Live Help Archives - Orange Internet Solutions</title>
	<link>https://orangeinternetsolutions.com/tag/crafty-syntax-live-help/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Crafty Syntax Live Help 3.4.7 Update Released</title>
		<link>https://orangeinternetsolutions.com/security-updates/crafty-syntax-live-help-3-4-7-update-released/</link>
		
		<dc:creator><![CDATA[Orange]]></dc:creator>
		<pubDate>Tue, 26 Aug 2014 17:31:39 +0000</pubDate>
				<category><![CDATA[Security & Updates]]></category>
		<category><![CDATA[chat]]></category>
		<category><![CDATA[Crafty Syntax]]></category>
		<category><![CDATA[Crafty Syntax Live Help]]></category>
		<category><![CDATA[Customer Support]]></category>
		<guid isPermaLink="false">http://miamihoster.com/?p=7436</guid>

					<description><![CDATA[<p>&#8220;Crafty Syntax Live Help 3.4.7 this is a maintenance release.&#8221; Crafty Syntax Live Help 3.4.7 (CSLH) is an open source live support solution that helps customer support with live help functionality that can be proactively pushed to visitors to your site or requested by the consumer. Crafty Syntax Live Help 3.4.7 includes a large range of features to [&#8230;]</p>
<p>The post <a href="https://orangeinternetsolutions.com/security-updates/crafty-syntax-live-help-3-4-7-update-released/">Crafty Syntax Live Help 3.4.7 Update Released</a> appeared first on <a href="https://orangeinternetsolutions.com">Orange Internet Solutions</a>.</p>
]]></description>
										<content:encoded><![CDATA[<blockquote>
<h4 style="text-align: center;"><em>&#8220;Crafty Syntax Live Help 3.4.7 this is a maintenance release.&#8221;</em></h4>
</blockquote>
<p><img loading="lazy" decoding="async" class="alignleft wp-image-4744 size-full" src="http://miamihoster.com/wp-content/uploads/2013/10/crafty-syntax-logo.gif" alt="Crafty Syntax Live Help 3.4.7 logo - Miami Hoster domains, web hosting and websites" width="100" height="100" /></p>
<p>Crafty Syntax Live Help 3.4.7 (CSLH) is an open source live support solution that helps customer support with live help functionality that can be proactively pushed to visitors to your site or requested by the consumer.</p>
<p>Crafty Syntax Live Help 3.4.7 includes a large range of features to allow multiple operators, multiple departments and multiple languages to be used.</p>
<p>Crafty Syntax Live Help 3.4.7 is free and is progammed in PHP with Mysql for the datatabase.</p>
<p>Other highlighted features include the ability to create your own questions, auto inviting visitors, referer tracking, page tracking, ability to view what the customer is typing as they type, multiple chat sessions, sound alert, leave a message if offline, push urls, quick responses, Customizable graphics, and multiple operators.</p>
<h2>Changes Details</h2>
<ul>
<li>Added the CRM features for gathering customer data from visitors to website even when offline.</li>
</ul>
<p>[otw_is sidebar=otw-sidebar-8]</p>
<table width="100%">
<tbody>
<tr>
<td valign="top" width="50%">
<h2>More Information</h2>
<ul>
<li><span style="color: #333333; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif; font-size: small;"><strong>Try Online Demo</strong><br />
<a title="Crafty Syntax Live Help 3.4.7 Demo - Softaculous external link - miami hoster" href="http://www.softaculous.com/demos/Crafty_Syntax" target="_blank" rel="noopener noreferrer">Crafty Syntax Live Help 3.4.7 Demo</a> (Softaculous external link)<br />
Crafty Syntax Live Help 3.4.7 Changelog (External link)<br />
<a title="Crafty Syntax Live Help 3.4.7 Official Website - miami hoster" href="http://www.craftysyntax.com/index.php" target="_blank" rel="noopener noreferrer">Official Website</a> (External link)</span></li>
<li><span style="color: #333333; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif; font-size: small;"><strong>Start Crafty Syntax Live Help 3.4.7</strong><br />
Run Crafty Syntax Live Help 3.4.7 from your domain and hosting service. <a title="Register a domain to start Office Group" href="http://miamihoster.com/client_area/domainchecker.php">Register a Domain Name</a> if you don&#8217;t have one and choose one of our <a title="Web Hosting Comparison Chart" href="http://miamihoster.com/services/web-hosting-cloud-services/web-hosting-chart/">Hosting Plans</a> to Crafty Syntax Live Help 3.4.7</span></li>
<li><span style="color: #333333; font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif; font-size: small;"><strong>Hosted Crafty Syntax Live Help 3.4.7</strong><br />
<a title="Group Office stand alone" href="http://miamihoster.com/contact-us/">Contact us</a> if you don&#8217;t need a domain or hosting service, but want the Crafty Syntax Live Help 3.4.7</span></li>
</ul>
</td>
<td valign="top" width="50%">[otw_is sidebar=otw-sidebar-7]</td>
</tr>
</tbody>
</table>
<p>The post <a href="https://orangeinternetsolutions.com/security-updates/crafty-syntax-live-help-3-4-7-update-released/">Crafty Syntax Live Help 3.4.7 Update Released</a> appeared first on <a href="https://orangeinternetsolutions.com">Orange Internet Solutions</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Crafty Syntax Update 3.4.4 released</title>
		<link>https://orangeinternetsolutions.com/security-updates/crafty-syntax-update-3-4-4-released/</link>
		
		<dc:creator><![CDATA[Orange]]></dc:creator>
		<pubDate>Wed, 09 Oct 2013 19:35:17 +0000</pubDate>
				<category><![CDATA[Security & Updates]]></category>
		<category><![CDATA[Crafty Syntax Live Help]]></category>
		<category><![CDATA[Customer Support]]></category>
		<guid isPermaLink="false">http://miamihoster.com/crafty-syntax-update-3-4-4-released</guid>

					<description><![CDATA[<p>Crafty Syntax Live Help Update 3.4.4 two minor security issues were discovered.  Crafty Syntax Live Help (CSLH) is an open source live support solution that helps customer support with live help functionality that can be proactively pushed to visitors to your site or requested by the consumer. Crafty Syntax includes a large range of features [&#8230;]</p>
<p>The post <a href="https://orangeinternetsolutions.com/security-updates/crafty-syntax-update-3-4-4-released/">Crafty Syntax Update 3.4.4 released</a> appeared first on <a href="https://orangeinternetsolutions.com">Orange Internet Solutions</a>.</p>
]]></description>
										<content:encoded><![CDATA[<blockquote>
<h4 style="text-align: center;"><em>Crafty Syntax Live Help Update 3.4.4 two minor security issues were discovered. </em></h4>
</blockquote>
<p>Crafty Syntax Live Help (CSLH) is an open source live support solution that helps customer support with live help functionality that can be proactively pushed to visitors to your site or requested by the consumer.</p>
<p>Crafty Syntax includes a large range of features to allow multiple operators, multiple departments and multiple languages to be used. Crafty Syntax Live Help is free and is progammed in PHP with Mysql for the datatabase.</p>
<p>Other highlighted features include the ability to create your own questions, auto inviting visitors, referer tracking, page tracking, ability to view what the customer is typing as they type, multiple chat sessions, sound alert, leave a message if offline, push urls, quick responses, Customizable graphics, and multiple operators.</p>
<h2>Changes Details</h2>
<p>The Patch for both of these is detailed below.</p>
<p>Both of these security issues are VERY MINOR. The admin.php can not be accessed by the public so the remote file vulnerabiy can only be exploited by operators which makes it very hard to exploit.</p>
<p>Additonally it is not executed code so not remote code can be run on the server.</p>
<p>The full path disclosure allows hackers to see the full path to your installation but nothing more. This has been fixed as well.</p>
<p>+ Crafty Syntax Live Help &lt;= (2.*.* &amp; 3.*.*) RFI + Path Disclosure</p>
<ol>
<li>1) Remote File Include : admin.php<br />
<span style="font-size: 13px;">if(!(isset($UNTRUSTED[&#8216;page&#8217;]))){ $UNTRUSTED[&#8216;page&#8217;] = &#8220;scratch.php&#8221;; }<br />
</span><span style="font-size: 13px;"><span style="font-size: 13px;">http://localhost/path/admin.php?page=[RFI]</span></span>&nbsp;</li>
<li><span style="font-size: 13px;">2) Full Path Disclosure: xmlhttp.php<br />
</span><span style="font-size: 13px;">Dork: inurl:&#8221;/xmlhttp.php&#8221; Notice: Undefined index: whattodo in</span></li>
</ol>
<p>&nbsp;</p>
<h2>Patch for Above</h2>
<ol>
<li>Open up admin.php and update line #45 to be:<br />
<span style="font-size: 13px;"><span style="font-size: 13px;">&lt;frame src=&#8221;&lt;?php echo $page; ?&gt;?help=&lt;?php echo $UNTRUSTED[&#8216;help&#8217;] . $alttab; ?&gt;&#8221; name=&#8221;contents&#8221; scrolling=&#8221;AUTO&#8221; border=&#8221;0&#8243; marginheight=&#8221;0&#8243; marginwidth=&#8221;0&#8243; NORESIZE&gt;</span></span>&nbsp;</p>
<p><span style="font-size: 13px;">add these lines after line #38:<br />
</span><span style="font-size: 13px;">$page = &#8220;scratch.php&#8221;;<br />
</span><span style="font-size: 13px;">if($UNTRUSTED[&#8216;page&#8217;]==&#8221;scratch.php&#8221;){ $page = &#8220;scratch.php&#8221;; }<br />
</span><span style="font-size: 13px;">if($UNTRUSTED[&#8216;page&#8217;]==&#8221;mastersettings.php&#8221;){ $page = &#8220;mastersettings.php&#8221;; }<br />
</span><span style="font-size: 13px;">if($UNTRUSTED[&#8216;page&#8217;]==&#8221;help.php&#8221;){ $page = &#8220;help.php&#8221;; }<br />
</span><span style="font-size: 13px;">if($UNTRUSTED[&#8216;page&#8217;]==&#8221;edit_layer.php&#8221;){ $page = &#8220;edit_layer.php&#8221;; }<br />
</span><span style="font-size: 13px;">if($UNTRUSTED[&#8216;page&#8217;]==&#8221;edit_smile.php&#8221;){ $page = &#8220;edit_smile.php&#8221;; }<br />
</span><span style="font-size: 13px;">if($UNTRUSTED[&#8216;page&#8217;]==&#8221;operators.php&#8221;){ $page = &#8220;operators.php&#8221;; }<br />
</span><span style="font-size: 13px;">if($UNTRUSTED[&#8216;page&#8217;]==&#8221;departments.php&#8221;){ $page = &#8220;departments.php&#8221;; }<br />
</span><span style="font-size: 13px;">if($UNTRUSTED[&#8216;page&#8217;]==&#8221;data.php&#8221;){ $page = &#8220;data.php&#8221;; }<br />
</span><span style="font-size: 13px;"><span style="font-size: 13px;">if($UNTRUSTED[&#8216;page&#8217;]==&#8221;modules.php&#8221;){ $page = &#8220;modules.php&#8221;; }</span></span>&nbsp;</li>
<li><span style="font-size: 13px;">Open up xmlhttp.php and change line #52:<br />
</span><span style="font-size: 13px;"><span style="font-size: 13px;">if(empty($UNTRUSTED[&#8216;whattodo&#8217;])){ $UNTRUSTED[&#8216;whattodo&#8217;] = &#8220;&#8221;; }</span></span>&nbsp;</p>
<p><span style="font-size: 13px;">remove line #53:<br />
</span><span style="font-size: 13px;">$whattodo = &#8220;&#8221;;</span></li>
</ol>
<h2>Files Changed</h2>
<ul>
<li>setup.php</li>
<li><span style="font-size: 13px;">xmlhttp.php</span></li>
<li><span style="font-size: 13px;">admin.php</span></li>
<li><span style="font-size: 13px;">navigation.php,</span></li>
</ul>
<h2>More Information</h2>
<ul>
<li><strong>Try Online Demo</strong>:<br />
<a title="Crafty Syntax Live Help Demo - Softaculous external link" href="http://demos1.softaculous.com/Crafty_Syntax/login.php?err=1" target="_blank" rel="noopener noreferrer">Crafty Syntax Live Help</a> (Softaculous<em> external link</em>)<br />
<a title="Crafty Syntax Live Help changelog - Oficial website external link" href="http://www.craftysyntax.com/CHANGELOG.txt" target="_blank" rel="noopener noreferrer">Crafty Syntax Live Help Changelog</a> (<em>Official website, external link</em>)</li>
</ul>
<ul>
<li><strong>Start Crafty Syntax Live Help</strong>:<br />
<span style="font-size: 13px;">In order to use Crafty Syntax Live Help you need a domain name (ex. yoursite.com) and web hosting service.<br />
If you don&#8217;t have a domain name </span><a style="font-size: 13px;" title="Register a domain to start Office Group" href="http://miamihoster.com/client_area/domainchecker.php">Register a Domain Name</a><span style="font-size: 13px;">.<br />
</span>To install Crafty Syntax Live Help choose one of our <a title="Web Hosting Comparison Chart" href="http://miamihoster.com/services/web-hosting-cloud-services/web-hosting-chart/">hosting plans</a>. (all our packages includes <em>Softaculous</em>).</li>
</ul>
<ul>
<li><strong style="font-size: 13px;">Hosted<strong> <strong>Crafty Syntax Live Help</strong></strong><br />
</strong><a style="font-size: 13px;" title="Group Office stand alone" href="http://miamihoster.com/contact-us/"><strong>Contact us</strong></a><span style="font-size: 13px;"> if you </span><strong style="font-size: 13px;">don&#8217;t need a domain or hosting service</strong><span style="font-size: 13px;">, and want to use <strong>Crafty Syntax Live Help</strong></span><span style="font-size: 13px;"> anyway.</span></li>
</ul>
<div>[otw_is sidebar=otw-sidebar-7]</div>
<p>[otw_is sidebar=otw-sidebar-8]</p>
<table width="100%">
<tbody>
<tr>
<td colspan="2">
<h2>Blog: News &amp; Updates</h2>
</td>
</tr>
<tr>
<td valign="top" width="50%">[otw_is sidebar=otw-sidebar-5]</td>
<td valign="top" width="50%">[otw_is sidebar=otw-sidebar-6]</td>
</tr>
</tbody>
</table>
<div>[otw_is sidebar=otw-sidebar-9]</div>
<p>The post <a href="https://orangeinternetsolutions.com/security-updates/crafty-syntax-update-3-4-4-released/">Crafty Syntax Update 3.4.4 released</a> appeared first on <a href="https://orangeinternetsolutions.com">Orange Internet Solutions</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
