| ||||||||||
Shopping cart software Solutions for online shops and malls | ||||||||||
|
X-Cart Home | FAQ | Forum rules | Calendar | User manuals | Login |
Warning: Iframe based attacks using stolen FTP access info | ||||
|
|
Thread Tools |
#1
|
|||||||
|
|||||||
Warning: Iframe based attacks using stolen FTP access info
There seems to be a hacker out there (looks like they are from Egypt) targeting X-Cart sites with iframe based attacks. Basically they are gaining FTP access to a site and adding an iframe to existing index files, or adding new index files in all of the directories. The iframe loads a virus to anyone who accesses the site, both the admin side and the customer side. As you can imagine, this can be extremely damaging to your store if all of your customers get hit with this virus (particularly if they don't have anti-virus software). If you suddenly start to get a 'secure and insecure' warning in the admin, and see something loading other than your domain, close your browser immediately and contact your host.
The accounts that were hacked (the ones I know of) had FTP passwords that are just about impossible to hack, which means the account data was stolen/intercepted. Where it was stolen from is something myself and a few others are investigating as we speak. In any event, now would be a VERY good time to change your FTP password, particularly if you have had work done on your site by anyone outside your organization. This can usually be done via your host's control panel. You can also block these specific IP addresses which seem to be the source of some of the attacks (although these are probably just a proxy): 41.232.70.12 41.232.70.190 41.232.69.30 41.232.69.144 This is a serious threat, so please treat it as such - don't just dismiss this as 'it can't happen to me'.
__________________
Padraic Ryan Ryan Design Studio Professional E-Commerce Development |
|||||||
#2
|
|||||||||
|
|||||||||
Re: Warning: Iframe based attacks using stolen FTP access info
In my version (4.1.10) the following security measure is implemented in the config.php file.
Code:
Should this not stop the attack which you are talking about? |
|||||||||
#3
|
|||||||
|
|||||||
Re: Warning: Iframe based attacks using stolen FTP access info
Na, that keeps X-Cart from being shown IN an Iframe, I don't think it prevents an iframe from being shown IN X-Cart...
__________________
Padraic Ryan Ryan Design Studio Professional E-Commerce Development |
|||||||
#4
|
|||||||
|
|||||||
Re: Warning: Iframe based attacks using stolen FTP access info
photo, that prevents the shopping cart from being displayed within an iframe.
__________________
Emerson █ Total Server Solutions LLC- Quality X-Cart Hosting █ Recommended X-Cart Hosting Provider - US and UK servers █ Does your host backup your site? We do EVERY HOUR!!! █ Shared Hosting | Managed Cloud | Dedicated Servers |
|||||||
#5
|
|||||||||
|
|||||||||
Re: Warning: Iframe based attacks using stolen FTP access info
I see. Were these hacks in the latest versions (4.1.10 & 4.1.11) of Xcart?
|
|||||||||
#6
|
|||||||||
|
|||||||||
Re: Warning: Iframe based attacks using stolen FTP access info
I've seen the hacks in 4.0 sites and the latest 4.1 sites, with hackersafe and every security measure possible, including ftp p/ws of strength 100.
__________________
Paul Dodman e-business & m-commerce consultant w: www.luminointernet.com e: xcart@luminointernet.com Professional X-Cart help, advice, support and services, specialists in Mobile X-Cart. |
|||||||||
#7
|
|||||||||
|
|||||||||
Re: Warning: Iframe based attacks using stolen FTP access info
Quote:
That is not good. Hopefully someone can figure out how these clowns are getting the access info. |
|||||||||
#8
|
|||||||
|
|||||||
Re: Warning: Iframe based attacks using stolen FTP access info
Wow, that's a serious comprimise....
Thanks for letting us know Padraic! |
|||||||
#9
|
|||||||
|
|||||||
Re: Warning: Iframe based attacks using stolen FTP access info
Paul,
What I've seen are iframes loading a live-counter URL. Is that what you have seen as well? photo, This is not an x-cart vulnerability but FTP passwords are being leaked somewhere.
__________________
Emerson █ Total Server Solutions LLC- Quality X-Cart Hosting █ Recommended X-Cart Hosting Provider - US and UK servers █ Does your host backup your site? We do EVERY HOUR!!! █ Shared Hosting | Managed Cloud | Dedicated Servers |
|||||||
#10
|
|||||||
|
|||||||
Re: Warning: Iframe based attacks using stolen FTP access info
How do you mean Emerson?
|
|||||||
|
|||
X-Cart forums © 2001-2020
|