Card Production: Can PHP Be Upgraded When Customer Reports Vulnerability Found With Their Security Scan?

Customers will report that they ran a security scan and it finds that their PHP is outdated and they ask if it can be upgraded.

 

First thing you want to find out is:  What version of CS Gold are they currently on?

 

1.) If they are not on the newest version we can suggest they can upgrade which will bring them to the most recently used version tested with CS Gold which can be found in release notes.

2. If they ARE on the newest version available of CS Gold they can upgrade to the more recent version of the PHP available on the PHP website and we could assist with that, but they need to understand that with it not being a tested version supplied via the upgrade process there is no guarantee what it could or could not affect as far as errors or other system issues. If they understand the risk and want assistance schedule time and it should only take 15 - 20 minutes to complete, down time is as long as it takes to get the files in place. 

 

A.) To upgrade php outside of what is supplied by CS Gold upgrade you will go to: https://windows.php.net/downloads/releases/

B.) Download the latest php-7.4.XX-Win32-vc15-x64.zip at the time of this article php-7.4.33-Win32-vc15-x64.zip is the version to download

w1.png

C.) Upload to the customers web server and if their scan caught the tps it can be applied to the tps as well.

*Make after uploading in the properties tab it doesn't show media blocked, if it does make sure to select unblock and apply. 

D.)  Unzip the contents of the php file uploaded onto the system.

E.) Copy the PHP folder and make a backup of it can call it PHPOLD. Found in: D:\Program Files\PHP

w2.png

F.) Stop Apache services and ensure nothing in details tab of task manager shows httpd.exe or PHP.exe, if it does be sure to kill those. 

w3.png

G.) Copy contents from the PHP unzipped folder into the PHP folder (D:\Program Files\PHP)

H.) Start Apache

I.) Open command prompt as Admin and run php -v it will return the PHP version and confirms that it was successful.

w4.png

J.) Have customer log in to system to ensure no issues that require reverting back.

If there are errors revert the changes made by stopping Apache, rename the PHP folder to PHPBAD, find the PHPOLD created in earlier steps, rename it to PHP, restart Apache and verify errors resolved. Inform customer at that point to await tested version release with next available CS Gold upgrade. 

 

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.

Have more questions?
Submit a request