Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

Warning: Iframe based attacks using stolen FTP access info

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #221  
Old 12-01-2008, 08:17 AM
 
Emerson Emerson is offline
 

X-Man
  
Join Date: Mar 2004
Location: Atlanta, GA
Posts: 2,209
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
Originally Posted by pauldodman
From what I can make out of the txt file, it'll strip out any hidden iframes those with 0 width and/or height or with the "hidden" attribute.
Would that then affect Firetank mods? Anything visible, and therefore possibly genuine, would be ok.

Interesting!
Will check it out further.
Will need to find a customer using one of these mods and ask for access to the admin side so I can test it out.
__________________
Emerson
Total Server Solutions LLC- Quality X-Cart Hosting
Recommended X-Cart Hosting Provider - US and UK servers
Does your host backup your site? We do EVERY HOUR!!!
Shared Hosting | Managed Cloud | Dedicated Servers
Reply With Quote
  #222  
Old 12-19-2008, 06:56 AM
 
dtherio dtherio is offline
 

Advanced Member
  
Join Date: Jan 2003
Location: Dallas, Texas
Posts: 84
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Hi folks,

I have just recently re-setup my x-cart store (actually in the process of getting it setup) and noticed this thread today. I wanted to comment that just last night I discovered one of my WordPress based sites had this exploit.

The exploit was in one of the posts, a post that I had made on the site back in early 2007 (the site has not been updated recently). Almost daily I would get emails of spammers posting spam comments on the site, however I do not allow comments to go live until approved.

I do not know how the exploit made it into my post as when building and accessing that site I only used a Mac. According to google (I had the warning show up when trying to access the site via Firefox) it claims my site is a source of an iframe exploit for 90 days.

FTP is not enabled on this site, just SFTP. I edited the post last night to remove the iframe and the traffic code (yep, they were checking how many page views my site got as well). I have also set the blog to require a user be registered before being able to post and require all users to be approved for their registration.

I expect the above steps will stop it on that site.

I mention this only to confirm that it happens on non-x-cart sites as well. Non of the other sites on this server had been compromised.

Dale
__________________
--
X-Cart 4.2, Fancy Categories, Affiliate
Reply With Quote
  #223  
Old 12-22-2008, 10:02 AM
 
shellshack shellshack is offline
 

Member
  
Join Date: Oct 2008
Posts: 15
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

I just got hit with an iframe attack at seashellshack.com

This is the destination [removed by mod]

No one had access to my ftp although I have not yet applied the new security patch.
__________________
4.1.11
Reply With Quote
  #224  
Old 12-22-2008, 10:04 AM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Please don't post links that appear in hacked sites.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #225  
Old 12-22-2008, 11:22 AM
 
shellshack shellshack is offline
 

Member
  
Join Date: Oct 2008
Posts: 15
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

It wasn't a link.

The "."s were replaced with "dot"s so everyone could use it to look for the problem on their sites. I might be a newb but I am not a complete idiot.
__________________
4.1.11
Reply With Quote
  #226  
Old 12-22-2008, 11:51 AM
 
balinor balinor is offline
 

Veteran
  
Join Date: Oct 2003
Location: Connecticut, USA
Posts: 30,253
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

It actually was a link it probably just didn't go anywhere if you modified it - I removed it before I looked at it as other not so bright people HAVE posted the iframe's links in this thread.
__________________
Padraic Ryan
Ryan Design Studio
Professional E-Commerce Development
Reply With Quote
  #227  
Old 12-23-2008, 06:36 AM
 
shellshack shellshack is offline
 

Member
  
Join Date: Oct 2008
Posts: 15
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

The Ip for my attacker is 67.238.189.236 out of winter park FL.

They injected iframes into all index, home, default and auth files plus admin/main, admin/admin/main, /include/include/login.php and more.

Then he changed the config file to collect credit card #s, added his IP as an allowed administrator and then hid that page from me.

This person is very familiar with xcart.
__________________
4.1.11
Reply With Quote
  #228  
Old 12-23-2008, 06:58 AM
 
EN4U EN4U is offline
 

eXpert
  
Join Date: Feb 2008
Location: AZ
Posts: 379
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

You have to wonder if that IP is part of this community and thru our discussions we are giving out info. That would totally suck. Anyway IP records for logins i assume can be gone through to verify if it exists so we aren't giving the hacker a home to watch us all.

Just a thought....

Anyways, I just got my sites all patched to the newest of security releases. I hope all is sealed up now for this and other forms of low life.
__________________
Regards, Dan
X-Cart Gold Version 4.1.10

1 - One page checkout
2 - Image Generator
3 - CSDEO Pro
4 - Shop By Price
5 - Next - Previous
6 - On Sale
7 - Shop By Price

8 - Froogle & Google Base Feed
9 - Buy Together
10 - Customer Loyalty Points
11 - Customer Reward Points
Customer Reward Points Referral Add-on
12 - Product Reviews
13 - Other Custom Modifications
----------------------
http://www.townsqjewelry.com/
http://www.eroticnights4u.com/ <---- Adult Oriented - Toys
Reply With Quote
  #229  
Old 12-28-2008, 10:37 AM
 
TA TA is offline
 

eXpert
  
Join Date: Apr 2006
Posts: 303
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

I just stumbled onto this thread. We were attacked on 10/8/08 by this same hacker. We noticed the insecure warning from IE. That was our first clue. I got on the phone right away with our server host and once I determined that files were changed, I closed down the web-site. Our host uploaded backup files to replace any that were changed, we changed all passwords and I shut down FTP access on our server. I rarely use FTP, so we are leaving it off for now. I usually work through CPanel file manager. Now that I know the extent of this, I am having our host run the SSH command from post #64 to make sure we didn't miss anything.

Has the source ever been figured out? I understand that we do not want to burn anybody at the stake, but I would like to know where the breech happened and if steps have been taken to help prevent this in the future.
__________________
v4.7.12
v5.4.x (In Dev)
Reply With Quote
  #230  
Old 02-21-2009, 11:32 PM
  WESH(UK)'s Avatar 
WESH(UK) WESH(UK) is offline
 

Member
  
Join Date: May 2006
Location: London-UK
Posts: 26
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Hey all

Did anybody ever figure this out in the end?
This is still happenening...
__________________
Richard Wraith
WESH UK Hosting
Tel: 0800 5 999 404
Web: http://wesh.uk
====================
UK Web Hosting with cPanel
===========================
FREE I.T SUPPORT & REMOTE DESKTOP
===========================
Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 01:03 PM.

   

 
X-Cart forums © 2001-2020