Results 1 to 4 of 4

hacker attack

This is a discussion on hacker attack within the osCommerce 2.2 Installation Help forums, part of the osCommerce 2.2 Forums category; Hi our front end admin panel was hijacked by hackers last week. Managed to get the password and email reset ...

      
  1. #1
    New Member www.gamedash.co.uk's Avatar
    Join Date
    Jan 2007
    Location
    Wakefield
    Posts
    7
    Rep Power
    0


    Default hacker attack

    Hi our front end admin panel was hijacked by hackers last week. Managed to get the password and email reset with hostrockets help and couldn't see any damage apart from images missing which we are still reinstalling.
    Got two emails today from wellsfargo bank though and it seems that pshing files were put into our files.
    Have located one of them but it shows as o bytes and cannot be opened or deleted. Using aceftp for file transfer and management. Any ideas how best to proceed.
    Paul
    Gamedash
    Quality games, toys and dvd from a small family based business on the net at www.gamedash.co.uk and in West Yorkshire.

  2. #2
    osCMax Developer

    michael_s's Avatar
    Join Date
    Jul 2002
    Location
    Phoenix, AZ
    Posts
    19,500
    Rep Power
    567


    Default Re: hacker attack

    The best way to proceed is to first find and close the hole used to hack your site. If you are using an older version of osCommerce, there are quite a few holes. Have your host backtrack the hack to find the source.

    Second, keeping only your configure.php files, refresh all your osC files from a backup made prior to the hack.

    Third, throughly check your account for any files that should not be there and remove them. If you cannot remove them via ftp, have your host remove them for you.
    Michael Sasek
    osCMax Developer


    osCmax installation service - Have our professionals install osCmax on your server - same day service!
    osCmax 2.0 User Manual - the must have beginners guide to osCmax v2.0

    Stay Up To Date with everything osCMax:
    Free osCMax Newsletters - Security notices, New Releases, osCMax News
    osCMax on Twitter - Up to the minute info as it happens. Know it first.

    osCmax Documentation

  3. #3
    New Member www.gamedash.co.uk's Avatar
    Join Date
    Jan 2007
    Location
    Wakefield
    Posts
    7
    Rep Power
    0


    Default Re: hacker attack

    Thanks. Have managed to destroy the offending file but will certainly go through the steps mentioned to secure the site. The file was in images and I think I read somewhere that the hackers replace your images with a program. There should be a simple fix to specify that images can only be a cerain type of file.
    Any idea where the download is.
    running PHP Version:4.3.11 (Zend: 1.3.0)
    if that helps.
    Quality games, toys and dvd from a small family based business on the net at www.gamedash.co.uk and in West Yorkshire.

  4. #4
    Member
    Join Date
    Feb 2007
    Posts
    31
    Rep Power
    0


    Default Re: hacker attack

    I don't know if they actually replace your image with a program, but I caught someone trying to place phpRemoteView in my images directory under the filename "down.php"...

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •