osCmax v2.5 User Manual
Results 1 to 6 of 6

New Hack?

This is a discussion on New Hack? within the osCmax v2 Installation issues forums, part of the osCmax v2.0 Forums category; I have had 2 clients in the last couple of days whose main page has been deleted. One client edited ...

      
  1. #1
    Member
    Join Date
    Jun 2008
    Posts
    73
    Rep Power
    4


    Default New Hack?

    I have had 2 clients in the last couple of days whose main page has been deleted.

    One client edited their page before I could see what was put in its place, the other clients had code I did not understand but looked to be cookie grabber type code.

    Is this a new hack going around?

  2. #2
    osCMax Development Team
    pgmarshall's Avatar
    Join Date
    Feb 2009
    Location
    London
    Posts
    2,678
    Rep Power
    49


    Smile Re: New Hack?

    Post the code that was put up on their site so we can take a look.

    Have you done the usual security proceedures ... renamed admin, .htaccess, permissions, etc. ?

    Are they running any other php software on the server?

    Which version of osCmax are you running?

    Regards,
    pgmarshall
    _______________________________

  3. #3
    Member
    Join Date
    Jun 2008
    Posts
    73
    Rep Power
    4


    Default Re: New Hack?

    I dont have a copy of the code but it was similar to if f[open] and the word cookies alot.

    Yes all security measures have been taken on both sites bar the renaming of the admin folder which has now been done.

    There is no other php software on 1 clients server, the other uses phplist

    The version is 2.0 and I am currently trying to find out where and how to upgrade to the latest version.

    Do you know if I can just follow these instructions? http://wiki.oscdox.com/upgrades

  4. #4
    osCMax Development Team
    pgmarshall's Avatar
    Join Date
    Feb 2009
    Location
    London
    Posts
    2,678
    Rep Power
    49


    Default Re: New Hack?

    If you are running 2.0 RC4 or anything below 2.0.4 ... you need to get rid of the filemanager and define languages files as these are known security holes ...

    The fix is easy - just delete the files ...

    Regards,
    pgmarshall
    _______________________________

  5. #5
    Member
    Join Date
    Jun 2008
    Posts
    73
    Rep Power
    4


    Default Re: New Hack?

    Those have been removed already

  6. #6
    osCMax Development Team
    pgmarshall's Avatar
    Join Date
    Feb 2009
    Location
    London
    Posts
    2,678
    Rep Power
    49


    Default Re: New Hack?

    Good!

    I have not heard of any new security issues on any of the osCommerce forks ...

    Without more info on the code inserted we are not going to get much further ... so you will just have to check your sites for new files ... change your passwords ... etc.

    What do to when you have been hacked.

    Regards,
    pgmarshall
    _______________________________

Similar Threads

  1. What the Hack?
    By BrandonScottishRegalia in forum osCmax v2 Installation issues
    Replies: 5
    Last Post: 09-17-2009, 01:09 PM
  2. Is this a hack?
    By pgmarshall in forum osCmax v2 Installation issues
    Replies: 6
    Last Post: 08-12-2009, 07:57 AM
  3. Hermes Hack
    By michael_s in forum New osCommerce Contributions
    Replies: 0
    Last Post: 09-17-2007, 11:11 AM
  4. QT Pro STS hack
    By michael_s in forum New osCommerce Contributions
    Replies: 0
    Last Post: 04-15-2007, 02:06 AM
  5. QT Pro STS hack
    By michael_s in forum New osCommerce Contributions
    Replies: 0
    Last Post: 04-13-2007, 08:00 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •