Results 1 to 10 of 46

Hybrid View

  1. #1
    Join Date
    May 2006
    Location
    Aberaeron, Ceredigion, Wales
    Posts
    72
    Plugin Contributions
    0

    Default Re: A VIRAL Problem!

    Quote Originally Posted by xt0rt
    I've seen similar posts like this one here and there... where is this crap coming from? Is there a website somewhere offering a compromised Zen download? Is this a problem on Windows servers only or all across the board?

    Just seems a bit off...
    No idea xOrt,

    My original zipped download came from the official ZC website. The only addition was the template I'm using plus a bug fixed file that was causing problems, but that was a seperate issue. That amended file came from the Dev Team. So no outside sources have been used for the actual ZC files. If there is a compromised copy floating around then I certainly didn't download it.

    G

  2. #2
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: A VIRAL Problem!

    I'm guessing that maybe some rogue script on the server may be doing it ... esp since the define_page_xxx files are in a folder that's CHMOD 777 .... making them writable by "world". While this is necessary if you wish to edit those file from your Admin interface, it also leaves the files somewhat at risk, depending on the server's configuration.

    This sort of thing is why hosts enable the "open_basedir restriction" settings in PHP... to prevent people from outside your account having any access to files inside your account, regardless of the permissions set. But that only works if the infiltrator is making their attempts via PHP.

    If the "attack" is entering via something at the filesystem level, you are likely still at risk.

    AT THE VERY LEAST, YOU SHOULD NOTIFY YOUR HOST ABOUT THIS... so they can take measures to stop it.... and maybe identify where it came from.

    Your server's errorlog may or may not help you see where rogue access attempts came from.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Nov 2004
    Location
    Norfolk, United Kingdom
    Posts
    3,036
    Plugin Contributions
    2

    Default Re: A VIRAL Problem!

    Why is the problem apparent in IE & Opera but not Firefox?
    I'm guessing that because it's called Hacktool.IE.Exploit that it seeks out vulnerabilities in IE (and Opera can be configured to work as if it was IE).
    It's probably related to running Active Content in IE.

    The worse problem is that if it is using Active Content and someone who doesn't have a Firewall comes to your site then their computer could get infected with this trojan.

    Vger

  4. #4
    Join Date
    May 2006
    Location
    Aberaeron, Ceredigion, Wales
    Posts
    72
    Plugin Contributions
    0

    Default Re: A VIRAL Problem!

    Thank you DrByte & Vger.

    I've just despatched an urgent message to the folks at the server end with a link to this thread for further info. Hopefully they'll be able to trace the source, and if they can't they should be able to contain the problem. I'm waiting for their response - I'll keep you posted.

    G

  5. #5
    Join Date
    May 2005
    Location
    Cheshire, UK
    Posts
    542
    Plugin Contributions
    3

    Default Re: A VIRAL Problem!

    G

    Check your images folder. I had a similar problem and found a PHP file had been uploaded into the images folder and this was being called by a virus which in turn propgated itself into other computers. I suspect the initial virus arrives by email and when you connect by FTP it uploads itself to the active directory on the server. From there it infects any computer which loads the site into a browser.

    Have a look at the DO NOT IGNORE POST I made some weeks ago in the hacks forum warning people about this.

    Hope this helps

    JJ

  6. #6
    Join Date
    May 2006
    Location
    Aberaeron, Ceredigion, Wales
    Posts
    72
    Plugin Contributions
    0

    Default Re: A VIRAL Problem!

    Quote Originally Posted by JollyJim
    G

    Check your images folder. I had a similar problem and found a PHP file had been uploaded into the images folder and this was being called by a virus which in turn propgated itself into other computers. I suspect the initial virus arrives by email and when you connect by FTP it uploads itself to the active directory on the server. From there it infects any computer which loads the site into a browser.

    Have a look at the DO NOT IGNORE POST I made some weeks ago in the hacks forum warning people about this.

    Hope this helps

    JJ
    Thanks Jim,
    Just checked and there are no php files in the "images" folder on the server. I doubt if any e-mails would have slipped past my defences anyway. I've been doing a bit of research and the indicators are that there's a vulnerability on the server side. Probably a rogue script there that's inserting the wilful code into lines of coding in programmes located on the server. I only hope that it's only done it once in the one file otherwise I've got a mess on my hands. I'm waiting for the server staff to come back to me with some info.

    I could really do without this

    G

  7. #7
    Join Date
    Nov 2004
    Location
    Norfolk, United Kingdom
    Posts
    3,036
    Plugin Contributions
    2

    Default Re: A VIRAL Problem!

    You won't want to hear this - but you need to shut your site down until it is resolved. If the trojan is on the server (which I think it is) then removing the code will do nothing - it will reinsert itself. Anyone coming to your site is at risk while this goes on.

    Vger

 

 

Similar Threads

  1. v151 Viral Coupon Code for emails/Facebook, Etc
    By wagnerguy in forum Discounts/Coupons, Gift Certificates, Newsletters, Ads
    Replies: 0
    Last Post: 23 Aug 2014, 10:35 PM
  2. UPS xml problem. Anybody else have this problem?
    By FrantzArt in forum Addon Shipping Modules
    Replies: 0
    Last Post: 2 Mar 2012, 11:10 PM
  3. Download Link Problem & Gift Card Problem too...
    By Miss Tiina in forum General Questions
    Replies: 2
    Last Post: 14 Mar 2009, 03:58 PM
  4. Customer said had problem creating account-dob problem
    By wtashby in forum General Questions
    Replies: 5
    Last Post: 1 Sep 2008, 11:38 AM
  5. Problem with Navigation In IE below 7.0! Minor Problem, need help!
    By bajanboost in forum Templates, Stylesheets, Page Layout
    Replies: 1
    Last Post: 6 Aug 2007, 04:09 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg