Skip to content

Commit

Permalink
本家でのセキュリティ報告SSL 3.0の脆弱性(POODLE攻撃)の対策で、SSL3.0の利用を行わないように修正しました。
Browse files Browse the repository at this point in the history
Signed-off-by: kimono <maeda@obitastar.co.jp>
  • Loading branch information
kimono committed Nov 14, 2014
1 parent 2063a3a commit aee45be
Show file tree
Hide file tree
Showing 4 changed files with 4 additions and 4 deletions.
2 changes: 1 addition & 1 deletion includes/modules/payment/authorizenet_aim.php
Expand Up @@ -573,7 +573,7 @@ function _sendRequest($submit_data) {
curl_setopt($ch, CURLOPT_POSTFIELDS, $data);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_TIMEOUT, 15);
curl_setopt($ch, CURLOPT_SSLVERSION, 3);
// curl_setopt($ch, CURLOPT_SSLVERSION, 3);
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); /* compatibility for SSL communications on some Windows servers (IIS 5.0+) */
if (CURL_PROXY_REQUIRED == 'True') {
$this->proxy_tunnel_flag = (defined('CURL_PROXY_TUNNEL_FLAG') && strtoupper(CURL_PROXY_TUNNEL_FLAG) == 'FALSE') ? false : true;
Expand Down
2 changes: 1 addition & 1 deletion includes/modules/payment/authorizenet_echeck.php
Expand Up @@ -583,7 +583,7 @@ function _sendRequest($submit_data) {
curl_setopt($ch, CURLOPT_POSTFIELDS, $data);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_TIMEOUT, 15);
curl_setopt($ch, CURLOPT_SSLVERSION, 3);
// curl_setopt($ch, CURLOPT_SSLVERSION, 3);
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE); /* compatibility for SSL communications on some Windows servers (IIS 5.0+) */
if (CURL_PROXY_REQUIRED == 'True') {
$this->proxy_tunnel_flag = (defined('CURL_PROXY_TUNNEL_FLAG') && strtoupper(CURL_PROXY_TUNNEL_FLAG) == 'FALSE') ? false : true;
Expand Down
Expand Up @@ -307,7 +307,7 @@ function curl_process($data)
curl_setopt ($ch, CURLOPT_CAINFO, $key);
curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, false);
curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, false);
curl_setopt ($ch, CURLOPT_SSLVERSION, 3);
// curl_setopt ($ch, CURLOPT_SSLVERSION, 3);
curl_setopt ($ch, CURLOPT_RETURNTRANSFER, true);


Expand Down
2 changes: 1 addition & 1 deletion includes/modules/payment/paypal/paypal_curl.php
Expand Up @@ -56,7 +56,7 @@ class paypal_curl extends base {
CURLOPT_FOLLOWLOCATION => FALSE,
CURLOPT_SSL_VERIFYPEER => FALSE,
CURLOPT_SSL_VERIFYHOST => 2,
CURLOPT_SSLVERSION => 3,
// CURLOPT_SSLVERSION => 3,
CURLOPT_FORBID_REUSE => TRUE,
CURLOPT_FRESH_CONNECT => TRUE,
CURLOPT_POST => TRUE,
Expand Down

0 comments on commit aee45be

Please sign in to comment.