Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Shopping carts hacked


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Shopping carts hacked
Reply
 
Thread Tools
Old 11-02-2006, 09:15   #1
Now a pensioner
 
j52c's Avatar
 
Join Date: Nov 2004
Location: next door to my neighbour
Posts: 247
j52c is a name known to allj52c is a name known to allj52c is a name known to allj52c is a name known to allj52c is a name known to allj52c is a name known to allj52c is a name known to allj52c is a name known to all
Shopping carts hacked

Hi.

Are their any users of X-cart shopping cart system on here?

It would appear over the last 4 to 6 weeks hackers are targetting them as some have been rendered unusable by hackers exploiting a flaw in Awstats on web servers.

some entries in web error logs look like this:-

/blog/xmlsrv/xmlrpc.php 30 -
/blogs/xmlsrv/xmlrpc.php 30 -
/xmlrpc/xmlrpc.php 28 -
/xmlsrv/xmlrpc.php 27 -
//awstats.pl 2 -
//awstats/awstats.pl 2 -
//cgi-bin/awstats/awstats.pl 2 -
/mysqladmin/main.php 2 -
/dbadmin/main.php 2 -
__________________
Regards.

Jim.
www.freebits.co.uk
j52c is offline   Reply With Quote
Old 11-02-2006, 15:00   #2
Legal Alien
 
Join Date: Jun 2003
Services: Cablevision
Posts: 8,126
SMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronze
SMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronzeSMHarman is cast in bronze
Re: Shopping carts hacked

AWstats is separate to xcart and would be an attack on that application that runs on many servers, not just xcart servers.

xcart is vunerable to hacking as is any other shopping cart site, peoples credit card information is stored in the database, it can cause financial hardship while your site is down, reputational loss / risk as you are off line and know to have been hacked.

Did you change the SALT code when you first inistalled the cart. This will change the encryiption keys and make it harder to hack. Of course if your site is up and running changing this key is difficult as it will trash all the passwords.

Have you set the permissions on all folders correctly

What folder is your xcart running in? Hopefully not blah.com/xcart/shop.php the path gives a clear clue to which codebase the hacker is trying to get into. The best place to run the shop is actually in the root public_html folder, helps SEO too.

Have you password protected the provider and the admin folder (better still renamed them and password protected them (using HTAccess or simpler still using CPanel to write the HT access)

Does your robots .txt exclude the folders mentioned above.

Have you disabled indexes in the other folders?

If you do all the above and back up your code base and database regularly you have less to worry about. You should also patch your xcart with the security fixes sent out.

URL (702) Error Hits Referers
/xmlrpc.php 14 -
/blogs/xmlsrv/xmlrpc.php 10 -
/xmlsrv/xmlrpc.php 8 -
/blog/xmlsrv/xmlrpc.php 8 -
/_vti_inf.html 8 -
/wordpress/xmlrpc.php 8 -
/blog/xmlrpc.php 8 -
/xmlrpc/xmlrpc.php 8 -
/_vti_bin/shtml.exe/_vti_rpc 8 -
/drupal/xmlrpc.php 8 -
/phpgroupware/xmlrpc.php 8 -
/scgi-bin/awstats/awstats.pl 7 -
/cgi-bin/awstats/awstats.pl 6 -
/cgi-bin/awstats.pl 5 -
/blogs/xmlrpc.php 5 -
/scgi-bin/stats/awstats.pl 4 -
/cgi/awstats/awstats.pl 4 -
/stats/awstats.pl 4 -
/scripts/awstats.pl 4 -
/cgi-bin/stats/awstats.pl 4 -
/scgi-bin/awstats.pl 4 -
/scgi/awstats/awstats.pl 4 -

My log is equally bad, these are 404s though so not much can happen if they see a 404.

Oh BTW - yes I run XCart
SMHarman is online now   Reply With Quote
Old 11-02-2006, 15:25   #3
Now a pensioner
 
j52c's Avatar
 
Join Date: Nov 2004
Location: next door to my neighbour
Posts: 247
j52c is a name known to allj52c is a name known to allj52c is a name known to allj52c is a name known to allj52c is a name known to allj52c is a name known to allj52c is a name known to allj52c is a name known to all
Re: Shopping carts hacked

Hi.

On this site, going to install the new version of X-cart and change the salt code once installed, as you say, trying to change it when live would be a pain. I have the products backed up so not a problem.
Too many files were changed, mainly te skin folder, so easier to start from scratch.

Another site I operate is quite safe as I have already done most of the things you have suggested, was in the process of doing it with this one, but it would appear I was a little late.

Here is a online tool to create .htaccess files if none users cpanel
http://www.htaccesstools.com/

We don't store credit card info on the server, orders are deleted once processed.

Tanks for the tips
__________________
Regards.

Jim.
www.freebits.co.uk
j52c is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 19:26.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)