osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 
 

hacker attack

This is a discussion on hacker attack within the osCommerce 2.2 Installation Help forums, part of the osCommerce 2.2 Forums category; Hi our front end admin panel was hijacked by hackers last week. Managed to get the password and email reset ...


Go Back   osCommerce and osCMax shopping cart software forums > osCommerce 2.2 Forums > osCommerce 2.2 Installation Help

Register FAQ Members List Calendar Mark Forums Read


Free community membership! Fast easy FREE membership
Reply

 

LinkBack Thread Tools
  #1  
Old 09-03-2007, 06:02 AM
www.gamedash.co.uk's Avatar
New Member
 
Join Date: Jan 2007
Location: Wakefield
Posts: 7
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
www.gamedash.co.uk is on a distinguished road
Default hacker attack

Hi our front end admin panel was hijacked by hackers last week. Managed to get the password and email reset with hostrockets help and couldn't see any damage apart from images missing which we are still reinstalling.
Got two emails today from wellsfargo bank though and it seems that pshing files were put into our files.
Have located one of them but it shows as o bytes and cannot be opened or deleted. Using aceftp for file transfer and management. Any ideas how best to proceed.
Paul
Gamedash
__________________
Quality games, toys and dvd from a small family based business on the net at www.gamedash.co.uk and in West Yorkshire.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Advertisement
  #2  
Old 09-03-2007, 01:21 PM
michael_s's Avatar
osCMax Developer

 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 11,074
Thanks: 81
Thanked 348 Times in 327 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default Re: hacker attack

The best way to proceed is to first find and close the hole used to hack your site. If you are using an older version of osCommerce, there are quite a few holes. Have your host backtrack the hack to find the source.

Second, keeping only your configure.php files, refresh all your osC files from a backup made prior to the hack.

Third, throughly check your account for any files that should not be there and remove them. If you cannot remove them via ftp, have your host remove them for you.
__________________
Michael Sasek
osCMax Developer


  • osCMax Templates - Hundreds of premium quality templates designed for osCMax 2. Loyalty discounts up to 30% off!
    Each purchase supports the osCMax project with much needed funds!

  • xShop for osCMax - Windows Based osCMax administration. Improved workflow, security, speed and convenience.

  • osCMax Hosting - From basic hosting to High Availability, Load Balanced arrays, the most experienced osCMax host. Default multi server configuration for exceptional performance!

  • osCMax Template Tutorial - Learn how to make your own custom templates and how to use the powerful features of the osCMax template system.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3  
Old 09-04-2007, 03:44 AM
www.gamedash.co.uk's Avatar
New Member
 
Join Date: Jan 2007
Location: Wakefield
Posts: 7
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
www.gamedash.co.uk is on a distinguished road
Default Re: hacker attack

Thanks. Have managed to destroy the offending file but will certainly go through the steps mentioned to secure the site. The file was in images and I think I read somewhere that the hackers replace your images with a program. There should be a simple fix to specify that images can only be a cerain type of file.
Any idea where the download is.
running PHP Version:4.3.11 (Zend: 1.3.0)
if that helps.
__________________
Quality games, toys and dvd from a small family based business on the net at www.gamedash.co.uk and in West Yorkshire.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4  
Old 10-12-2007, 11:53 AM
Member
 
Join Date: Feb 2007
Posts: 31
Thanks: 2
Thanked 2 Times in 2 Posts
Rep Power: 0
Autoegocrat is on a distinguished road
Default Re: hacker attack

I don't know if they actually replace your image with a program, but I caught someone trying to place phpRemoteView in my images directory under the filename "down.php"...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Advertisement
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -8. The time now is 10:54 PM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO
http://www.oscmax.com/forums/
Copyright 2008 osCMax