Follow us on Twitter X-Cart on Facebook Wiki
Shopping cart software Solutions for online shops and malls
 

Warning: Iframe based attacks using stolen FTP access info

 
Reply
   X-Cart forums > News and Announcements
 
Thread Tools
  #101  
Old 10-23-2008, 08:24 PM
  bigredseo's Avatar 
bigredseo bigredseo is offline
 

X-Man
  
Join Date: Oct 2002
Location: Omaha, NE, USA
Posts: 2,364
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

I have contacted Quest as the IP number was tracing to them, however they are unable to assist via phone. I was forced to enter an email at abuse@questip.net and provide logs. Any other hosts are encouraged to do the same, or if you wish to provide the IP numbers used in your attack (minus user information), please PM me and I will add it to my open ticket with Quest.

I have also contacted the security team at our data center (the planet) and they are actively blocking the IP number in their network currently.
__________________
Conor Treacy - Big Red SEO - @bigredseo
Search Engine Optimization & Internet Marketing - We Bring Your Website Out Of Hiding!
If you can't be found on Google, Bing or Yahoo, you pretty much don't exist on the Internet.
Omaha SEO Office with National & Local SEO Services
Hourly Consulting - great for SEO Disaster Recovery, Audits and DIY Guidance
Reply With Quote
  #102  
Old 10-23-2008, 08:59 PM
 
Emerson Emerson is offline
 

X-Man
  
Join Date: Mar 2004
Location: Atlanta, GA
Posts: 2,209
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
Originally Posted by Emerson
Their IP has now changed too.
The most recent one is 71.38.117.19

Hi Conor,
Yes I had seen the change of IP and had posted it yesterday.
Is the above the same one you have?
__________________
Emerson
Total Server Solutions LLC- Quality X-Cart Hosting
Recommended X-Cart Hosting Provider - US and UK servers
Does your host backup your site? We do EVERY HOUR!!!
Shared Hosting | Managed Cloud | Dedicated Servers
Reply With Quote
  #103  
Old 10-23-2008, 11:09 PM
  bigredseo's Avatar 
bigredseo bigredseo is offline
 

X-Man
  
Join Date: Oct 2002
Location: Omaha, NE, USA
Posts: 2,364
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Yep - Same one. I hadn't noticed it in the posting - sorry dude.

Did you try contacting Quest too? I've had no response from them as of yet
__________________
Conor Treacy - Big Red SEO - @bigredseo
Search Engine Optimization & Internet Marketing - We Bring Your Website Out Of Hiding!
If you can't be found on Google, Bing or Yahoo, you pretty much don't exist on the Internet.
Omaha SEO Office with National & Local SEO Services
Hourly Consulting - great for SEO Disaster Recovery, Audits and DIY Guidance
Reply With Quote
  #104  
Old 10-24-2008, 12:31 AM
  pauldodman's Avatar 
pauldodman pauldodman is offline
 

X-Guru
  
Join Date: Jul 2003
Location: Spain / UK
Posts: 3,052
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Quote:
Other forums that I frequent are not reporting any new incidents of iFrame attacks either, so it sure seems limited to here on the X-Cart users from what I can tell.

That is interesting I believe. From what I can tell, this attack isn't specific to x-cart software - they are not getting in via any vulnerabilities in x-cart, they are just accessing via ftp and changing php files. They could in effect be attacking any website they like. BUT they are NOT.
Does this tell us anything?
This is happening to many different people, different hosts, different data centers, different developers, different versions, different ftp programs, different operating systems, etc, etc.

What is common? - the only thing I can see is the x-cart helpdesk.

It is good that QT have got involved in this discussion; I'm hoping we hear some results back soon from them following their checks.

What would be good to know is if there is anyone who has been attacked who has NOT used their x-cart helpdesk.
__________________
Paul Dodman
e-business & m-commerce consultant
w: www.luminointernet.com
e: xcart@luminointernet.com

Professional X-Cart help, advice, support and services, specialists in Mobile X-Cart.
Reply With Quote
  #105  
Old 10-24-2008, 12:47 AM
  gb2world's Avatar 
gb2world gb2world is offline
 

X-Wizard
  
Join Date: May 2006
Location: Austin, TX
Posts: 1,970
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

I've confirmed with XCART the ftp user access names I have provided them in the past. None of the ftp accounts I created for QT's use were used to gain ftp access to my server. I am fairly certain I have never given access to any other vendor the account that was used by the hackers to gain access. I've made it a practice to create additional ftp accounts for others who I need to give temporary access.
__________________
X-CART (4.1.9,12/4.2.2-3/4.3.1-2/4.4.1-5)-Gold
(CDSEO, Altered-Cart On Sale, BCSE Preorder Backorder, QuickOrder, X-Payments, BCSE DPM Module)
Reply With Quote
  #106  
Old 10-24-2008, 12:48 AM
  bigredseo's Avatar 
bigredseo bigredseo is offline
 

X-Man
  
Join Date: Oct 2002
Location: Omaha, NE, USA
Posts: 2,364
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

That's one of the concerns I have. I know that the iFrame attack has been around a number of years. I know in '2006 there was a rash of injections and that was mainly due to phpBB and postings on there, and in March 2008 there were some issues on Wordpress, but was later determined that it was when people allowed COMMENTS and the hackers/exploiters were just posting in the comments section. That was resolved by killing HTML codes in the comments area.

I'd be curious to see just how many things are in common between the various sites.

As a note of warning to those who are reading this thread and have not already done so - please change your passwords! http://strongpasswordgenerator.com - this is a decent site for generating passwords if you don't have a password generator on hand.
__________________
Conor Treacy - Big Red SEO - @bigredseo
Search Engine Optimization & Internet Marketing - We Bring Your Website Out Of Hiding!
If you can't be found on Google, Bing or Yahoo, you pretty much don't exist on the Internet.
Omaha SEO Office with National & Local SEO Services
Hourly Consulting - great for SEO Disaster Recovery, Audits and DIY Guidance
Reply With Quote
  #107  
Old 10-24-2008, 01:09 AM
  gb2world's Avatar 
gb2world gb2world is offline
 

X-Wizard
  
Join Date: May 2006
Location: Austin, TX
Posts: 1,970
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Is there a possibility that the hackers could post the code/virus in this forum?
__________________
X-CART (4.1.9,12/4.2.2-3/4.3.1-2/4.4.1-5)-Gold
(CDSEO, Altered-Cart On Sale, BCSE Preorder Backorder, QuickOrder, X-Payments, BCSE DPM Module)
Reply With Quote
  #108  
Old 10-24-2008, 01:24 AM
 
tradedvdshop tradedvdshop is offline
 

Advanced Member
  
Join Date: Jun 2007
Location: Kent UK
Posts: 30
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

Does anyone know if these will just affect index pages in the public_html folder or could it go further affecting the skin1 files ect?
__________________
X-Cart version 4.1.3
Blank DVD Blank Cd Blank Media Dvd Case
http://www.discworlduk.co.uk


Reply With Quote
  #109  
Old 10-24-2008, 01:44 AM
  gb2world's Avatar 
gb2world gb2world is offline
 

X-Wizard
  
Join Date: May 2006
Location: Austin, TX
Posts: 1,970
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

In my case - many index.html & index.php files were exploited - in many directories. It has been reported here that index files can be added to any directory. Also saw the hack in other files. If you have shell access - run the unix commands in post 64.
__________________
X-CART (4.1.9,12/4.2.2-3/4.3.1-2/4.4.1-5)-Gold
(CDSEO, Altered-Cart On Sale, BCSE Preorder Backorder, QuickOrder, X-Payments, BCSE DPM Module)
Reply With Quote
  #110  
Old 10-24-2008, 01:58 AM
 
tradedvdshop tradedvdshop is offline
 

Advanced Member
  
Join Date: Jun 2007
Location: Kent UK
Posts: 30
 

Default Re: Warning: Iframe based attacks using stolen FTP access info

ok thanks for that i will run it now and have a look!
__________________
X-Cart version 4.1.3
Blank DVD Blank Cd Blank Media Dvd Case
http://www.discworlduk.co.uk


Reply With Quote
Reply
   X-Cart forums > News and Announcements



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 07:47 AM.

   

 
X-Cart forums © 2001-2020