Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

Warning: Iframe based attacks using stolen FTP access info

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #71  
Old 10-23-2008, 11:10 AM
  bigredseo's Avatar 
bigredseo bigredseo is offline
 

X-Man
  
Join Date: Oct 2002
Location: Omaha, NE, USA
Posts: 2,364
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

There's two methods on the hosts list. While we don't use windows servers (only unix) and our staff mainly use Linux desktops, here's the deal on the windows hosts list:

The host (your web server guys) shoudl be checking that file for any anomilities, however the USERS file can also be affected:

http://en.wikipedia.org/wiki/Hosts_file

Basically the file should be BLANK or at a minimum, known IPs. These are generally used to speed up searches and destinations on the web. Some people edit this file when they are moving sites from one server to antoher and want to test things.

Anyway, the file shoudl be empty. Open the HOSTS file with Notepad and make sure the file doesn't have anything in it. If there's something in it, then esentially what it's doing is trying to reroute you to another location.

If for example it has "yahoo.com" and then an IP number beside it, then that's probably fraud. Delete the line, and let it pick up yahoo on it's own.
__________________
Conor Treacy - Big Red SEO - @bigredseo
Search Engine Optimization & Internet Marketing - We Bring Your Website Out Of Hiding!
If you can't be found on Google, Bing or Yahoo, you pretty much don't exist on the Internet.
Omaha SEO Office with National & Local SEO Services
Hourly Consulting - great for SEO Disaster Recovery, Audits and DIY Guidance
Reply With Quote
  #72  
Old 10-23-2008, 11:10 AM
 
Emerson Emerson is offline
 

X-Man
  
Join Date: Mar 2004
Location: Atlanta, GA
Posts: 2,209
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
Originally Posted by pixellogo
Yes please I beg of you to elaborate more on that local computer check.

I'll do your laundry mate.

/me hands you some stinky socks
__________________
Emerson
Total Server Solutions LLC- Quality X-Cart Hosting
Recommended X-Cart Hosting Provider - US and UK servers
Does your host backup your site? We do EVERY HOUR!!!
Shared Hosting | Managed Cloud | Dedicated Servers
Reply With Quote
  #73  
Old 10-23-2008, 11:17 AM
 
Manic Manic is offline
 

Senior Member
  
Join Date: Dec 2007
Posts: 127
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
Originally Posted by Emerson
Navigate to the directory at C:\WINDOWS\system32\drivers\etc
In there you will see a file called "hosts".
Open it with notepad and make sure that no entries have been made there.

A stock, untouched file looks like the one below:


If you see any entry other then 127.0.0.1 localhost your computer has been compromissed.

By editing that file a hacker can make your browser point to an IP that is not actually the IP where that site is hosted.

For example. Lets say that yoursite.com is supposed to point to 11.11.11.11
A hacker can edit the hosts files and add the following entry:
22.22.22.22 yoursite.com

So when you type yoursite.com in your browser, you will actualkly be visiting the site at 22.22.22.22 and not 11.11.11.11
This can be used to to further collect any logins you try at that site, etc...

Scary, huh?
Emerson, I opened my "hosts" file with notepad and only found this:
127.0.0.1 localhost

I am OK then?
__________________
X-Cart Gold 4.1.9
Smart Search (from Altered Cart)
DSEFU Pro
Product Meta Tags Plus
Category Meta Title Control
Latest Additions (BCSE)
Remember Me login
FireTank's Feed Manager
Lightbox (BCSE)
EWD Hosting
Reply With Quote
  #74  
Old 10-23-2008, 11:22 AM
  bigredseo's Avatar 
bigredseo bigredseo is offline
 

X-Man
  
Join Date: Oct 2002
Location: Omaha, NE, USA
Posts: 2,364
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Yes. If that's all that's in there, then you're fine.
__________________
Conor Treacy - Big Red SEO - @bigredseo
Search Engine Optimization & Internet Marketing - We Bring Your Website Out Of Hiding!
If you can't be found on Google, Bing or Yahoo, you pretty much don't exist on the Internet.
Omaha SEO Office with National & Local SEO Services
Hourly Consulting - great for SEO Disaster Recovery, Audits and DIY Guidance
Reply With Quote
  #75  
Old 10-23-2008, 11:24 AM
 
tradedvdshop tradedvdshop is offline
 

Advanced Member
  
Join Date: Jun 2007
Location: Kent UK
Posts: 30
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Ok now i understand my pc is all ok thank god.

I have looked at the ftp log file and it seems they gained access on the 1st october the only work i have had done in this period was by xcart support???
__________________
X-Cart version 4.1.3
Blank DVD Blank Cd Blank Media Dvd Case
http://www.discworlduk.co.uk


Reply With Quote
  #76  
Old 10-23-2008, 11:25 AM
 
Manic Manic is offline
 

Senior Member
  
Join Date: Dec 2007
Posts: 127
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Thank you!
But I guess I won't be doing any online banking until this whole thing blows over.
__________________
X-Cart Gold 4.1.9
Smart Search (from Altered Cart)
DSEFU Pro
Product Meta Tags Plus
Category Meta Title Control
Latest Additions (BCSE)
Remember Me login
FireTank's Feed Manager
Lightbox (BCSE)
EWD Hosting
Reply With Quote
  #77  
Old 10-23-2008, 11:27 AM
 
pixellogo pixellogo is offline
 

Advanced Member
  
Join Date: Oct 2005
Posts: 54
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Thanks for that info Emerson.

None of our units are compromised, it's driving us crazy how this punk has gotten access...

I wouldn't be surprised if he is an X-Cart copy holder and he's monitoring this forum...
__________________
Logo Design By Pixellogo
X-Cart 4.0.15
Reply With Quote
  #78  
Old 10-23-2008, 11:28 AM
 
pixellogo pixellogo is offline
 

Advanced Member
  
Join Date: Oct 2005
Posts: 54
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
Originally Posted by Emerson
/me hands you some stinky socks

*Peter trying to decide which Tide to use, with or without Febreeze... These are some stinky socks!*

__________________
Logo Design By Pixellogo
X-Cart 4.0.15
Reply With Quote
  #79  
Old 10-23-2008, 11:54 AM
 
Emerson Emerson is offline
 

X-Man
  
Join Date: Mar 2004
Location: Atlanta, GA
Posts: 2,209
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
Originally Posted by pixellogo
*Peter trying to decide which Tide to use, with or without Febreeze... These are some stinky socks!*


Might wanna go for pure bleach lol

As far as safe don't feel to safe if your hosts file has not been tempered with as there still could be other problems.

As far as I see there are only 2 ways here that this information has been obtained by the crooks

1. there has been a major security breach where a concentration on logins have been reached. This could be from a helpdesk of any developer that you have done business with and provided them with FTP login so they could work on your site.

2. Your computer is infected with a keylogger that is sending the login info to the hackers.


Until we find out for sure how they are getting these logins no one is safe unfortunately.
__________________
Emerson
Total Server Solutions LLC- Quality X-Cart Hosting
Recommended X-Cart Hosting Provider - US and UK servers
Does your host backup your site? We do EVERY HOUR!!!
Shared Hosting | Managed Cloud | Dedicated Servers
Reply With Quote
  #80  
Old 10-23-2008, 11:55 AM
  photo's Avatar 
photo photo is offline
 

X-Wizard
  
Join Date: Feb 2006
Location: UK
Posts: 1,146
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
Originally Posted by Emerson
Navigate to the directory at C:\WINDOWS\system32\drivers\etc
In there you will see a file called "hosts".
Open it with notepad and make sure that no entries have been made there.

A stock, untouched file looks like the one below:


If you see any entry other then 127.0.0.1 localhost your computer has been compromissed.

By editing that file a hacker can make your browser point to an IP that is not actually the IP where that site is hosted.

For example. Lets say that yoursite.com is supposed to point to 11.11.11.11
A hacker can edit the hosts files and add the following entry:
22.22.22.22 yoursite.com

So when you type yoursite.com in your browser, you will actualkly be visiting the site at 22.22.22.22 and not 11.11.11.11
This can be used to to further collect any logins you try at that site, etc...

Scary, huh?
Just checked mine and it has the following two entries,

127.0.0.1 localhost
::1 localhost

is the 2nd one anything to be concerned about?

Thanks
__________________
v4.1.10
In Dev v4.5.x


"If you don't keep an eye on your business, someone else will."
Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 05:53 AM.

   

 
X-Cart forums © 2001-2020