osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 

Spam through admin/mail.php/login.php?action=send_email_to_user

This is a discussion on Spam through admin/mail.php/login.php?action=send_email_to_user within the osCMax v1.7 Discussion forums, part of the osCMax v1.7 Forums category; Hello, I just had a spammer get into http://www.domain.com/admin/mail.php..._email_to_user and send out spam about Viagra to all the customers. Anyone ...



Find us on Facebook
Go Back   osCommerce and osCMax shopping cart software forums > osCMax v1.7 Forums > osCMax v1.7 Discussion

Connect with Facebook Register FAQDonate Members List Calendar Mark Forums Read


Reply

 

LinkBack Thread Tools
  4 links from elsewhere to this Post. Click to view. #1  
Old 11-10-2009, 07:53 AM
Lurker
 
Join Date: Sep 2007
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
jferezy is on a distinguished road
Default Spam through admin/mail.php/login.php?action=send_email_to_user

Hello,

I just had a spammer get into http://www.domain.com/admin/mail.php..._email_to_user and send out spam about Viagra to all the customers. Anyone else have this issue? Is there a way to fix this? I think it is a major issue that all of everyone's customer list is out there. I think this needs to be addressed. I just went to a few oscmax sites and viewed their customer list via this link. I removed my mail.php link for now.

Any help would be greatly appreciated...

Jason
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2  
Old 11-10-2009, 08:26 AM
michael_s's Avatar
osCMax Developer


 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 16,522
Thanks: 149
Thanked 652 Times in 558 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default Re: Spam through admin/mail.php/login.php?action=send_email_to_user

You need to upgrade your site. This is a known vulnerability that has been patched in the current version of osCMax:
r169 - oscmax2 - Project Hosting on Google Code

You can manually modify your application_top.php file with the changes shown on that page and it will close your vulnerability. It sounds like you are not subscribed to the security announcements list. I advise you subscribe now:
osCMax opt in

Also be sure to see this security announcement released yesterday:
Security Notice : osCMax 2.0.4 Released
__________________
Michael Sasek
osCMax Developer

*** Do not PM me requesting paid help. The only paid work I do is for AABox Web Hosting customers ***

Stay Up To Date with everything osCMax:
Free osCMax Newsletters - Security notices, New Releases, osCMax News
osCMax on Twitter - Up to the minute info as it happens. Know it first.

osCMax User Manual - osCMax Templates - Advanced Template Tutorial

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following 4 Users Say Thank You to michael_s For This Useful Post:
altenter (12-22-2009), calistared (11-23-2009), jmdesign (12-20-2009), met00 (12-29-2009)
  #3  
Old 12-23-2009, 08:52 PM
Fishman1908's Avatar
New Member
 
Join Date: Dec 2009
Location: Coventry England
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
Fishman1908 is on a distinguished road
Default Re: Spam through admin/mail.php/login.php?action=send_email_to_user

Hi, first post so please be gentle.

I came across this forum due to looking for help as we have also just experienced a huge spam email campaign through our customer base.

I have read quite a lot of the comments through this forum on the subjects but 99% of the advice is totally over my head, sorry.

I can see at the top of my OS pages it says V2.2 RC2 so I think I have quite an new updated package which I would have thought was already secure against known problems like this.

I have also had some one let me know privately that we are not secure by sending me a list of the first alphabetical page of all customers registered!

I have been on the link to the Wiki Doc but again, only a small amount makes sense to me

I have turned off the "tell a friend" which was easy but I cannot find an actual folder called Admin?

I could go on but this is long enough already but I'm sure you get the gist.

Please help and guide me if you can.


Robin
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4  
Old 12-23-2009, 09:17 PM
Fishman1908's Avatar
New Member
 
Join Date: Dec 2009
Location: Coventry England
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
Fishman1908 is on a distinguished road
Default Re: Spam through admin/mail.php/login.php?action=send_email_to_user

Further to my last post I have found a load of folders and one named "admin" in my file manager but when I click on it, it doesn't give me any options to rename it, delete or anything?

All the files were in gobblygook so I pressed the reset button and their now all in english

I'm learning by default here but a little scared I'll bugger something up and remove something I shouldn't.


Robin
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5  
Old 12-23-2009, 09:19 PM
michael_s's Avatar
osCMax Developer


 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 16,522
Thanks: 149
Thanked 652 Times in 558 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default Re: Spam through admin/mail.php/login.php?action=send_email_to_user

Quote:
Originally Posted by Fishman1908 View Post

I can see at the top of my OS pages it says V2.2 RC2 so I think I have quite an new updated package which I would have thought was already secure against known problems like this.
Your version is extremely old and outdated. RC2 is years old and obsolete (Released in 2005. The RC2 means Release Candidate 2.

You have a lot of problems because your site is not patched against known security holes. The quickest way to secure your admin is to institute a second layer of password protection. Most hosting control panels have a simple feature to password protect folders. Use it to protect your admin folder, as right now you are wide open to anyone browsing through your database.

Most likely your site has been hacked too. You should examine the files of your site closely. Look at the very top of each file, if you see a long line of random letters and numbers, that is bad news. Each of your files will need to be cleaned, or you will need to restore from a clean backup.
__________________
Michael Sasek
osCMax Developer

*** Do not PM me requesting paid help. The only paid work I do is for AABox Web Hosting customers ***

Stay Up To Date with everything osCMax:
Free osCMax Newsletters - Security notices, New Releases, osCMax News
osCMax on Twitter - Up to the minute info as it happens. Know it first.

osCMax User Manual - osCMax Templates - Advanced Template Tutorial

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6  
Old 12-23-2009, 09:35 PM
Fishman1908's Avatar
New Member
 
Join Date: Dec 2009
Location: Coventry England
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
Fishman1908 is on a distinguished road
Default Re: Spam through admin/mail.php/login.php?action=send_email_to_user

Thanks Michael,

I have only had the site up for a couple of months and the person who set it up for me (a so-called computer advisor) should have known how old it was and its weaknesses I would have thought.

Although it would be a total pain in the backside, would I not be better served getting the latest updated site and delete this one completely if its so old and obsolete and start a fresh.

Robin
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7  
Old 12-23-2009, 10:03 PM
Fishman1908's Avatar
New Member
 
Join Date: Dec 2009
Location: Coventry England
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
Fishman1908 is on a distinguished road
Default Re: Spam through admin/mail.php/login.php?action=send_email_to_user

Also, although I don't want to but feel I must now with what I know, close the site down.

Unlike other sites I've had, I can't find anywhere how to take it offline so it shows as under maintenance etc.

please advise.


Robin
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8  
Old 12-24-2009, 07:19 AM
michael_s's Avatar
osCMax Developer


 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 16,522
Thanks: 149
Thanked 652 Times in 558 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default Re: Spam through admin/mail.php/login.php?action=send_email_to_user

PM me a the url to your site. I am thinking you are not running osCMax... I would like to confirm the version you are running. You may not be able to send a PM until you have 5 posts though so you can email it to me via the site's contact_us page (the link is at the very bottom of this forum.)
__________________
Michael Sasek
osCMax Developer

*** Do not PM me requesting paid help. The only paid work I do is for AABox Web Hosting customers ***

Stay Up To Date with everything osCMax:
Free osCMax Newsletters - Security notices, New Releases, osCMax News
osCMax on Twitter - Up to the minute info as it happens. Know it first.

osCMax User Manual - osCMax Templates - Advanced Template Tutorial

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9  
Old 12-24-2009, 07:39 AM
Fishman1908's Avatar
New Member
 
Join Date: Dec 2009
Location: Coventry England
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
Fishman1908 is on a distinguished road
Default Re: Spam through admin/mail.php/login.php?action=send_email_to_user

Thanks Michael for your attention to this.

This reply is now my 5th post

I have had someone place the whole site off-line currently but I will pm you now.


Robin
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10  
Old 12-24-2009, 07:51 AM
Fishman1908's Avatar
New Member
 
Join Date: Dec 2009
Location: Coventry England
Posts: 6
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
Fishman1908 is on a distinguished road
Default Re: Spam through admin/mail.php/login.php?action=send_email_to_user

I have sent a PM although this site has not recorded it or shown me a copy of it

Let me know that you get it ok.

Robn
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Tags
mail.php, security, spam

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


LinkBacks (?)

LinkBack to this Thread: http://www.oscmax.com/forums/oscmax-v1-7-discussion/20994-spam-through-admin-mail-php-login-php-action-send_email_to_user.html

Posted By For Type Date
Shopping Cart software | ezOSCNews| eCommerce Software oscommerce This thread Refback 04-11-2010 10:51 PM
Shopping Cart software | ezOSCNews| eCommerce Software OsCommerce can send out spam via the Mailinglist function, without login. This thread Refback 03-10-2010 12:41 AM
osCommerce 2.2 RC2a bug | incubatec system status This thread Refback 02-11-2010 02:31 AM
[#OSC-1069] OsCommerce can send out spam via the Mailinglist function, without login. - osCommerce Issue Tracker This thread Refback 01-27-2010 02:17 AM

Similar Threads

Thread Thread Starter Forum Replies Last Post
Disable shopping cart action Pcelica osCMax v2 Installation issues 2 10-27-2009 01:38 PM
Admin Login Problem - my customer can't login, I can pram0310 osCMax v1.7 Installation 2 10-29-2004 10:46 AM
How do I set banner action? pram0310 osCMax v1.7 Discussion 4 09-20-2004 08:18 PM
Well crap... admin login not allowing login-no errors tauras911 osCMax v1.7 Installation 2 07-06-2004 11:12 PM
Please - e-mail with gift voucher - login client rogerbr osCMax v1.7 Discussion 2 10-03-2003 05:44 AM


All times are GMT -8. The time now is 07:28 PM.


Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO
Copyright 2010 osCmax
Inactive Reminders By Icora Web Design