Page 1 of 2 12 LastLast
Results 1 to 10 of 14
  1. #1
    Join Date
    Oct 2004
    Posts
    20
    Plugin Contributions
    0

    Default Customer information problem -- zenid

    I run a site with only digital downloads (http://www.liddysloft.com/boutique) and lately I've had a few customer names that come up as ordering different combinations of our free items over and over (ie. order #1: freebie #1, order # 2: freebies #1-4, etc.)

    I updated the site with the latest security fixes per the forum instructions as soon as the e-mail/announcement came out that they were needed.

    Is this something wrong with the ordering system or an attempt at hacking? I had a lady just this morning (first time) e-mail me and say she received e-mail confirmations of orders that she didn't place and she was VERY irate.

  2. #2
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: Site hacked?

    Doesn't sound like a hack. Sounds like spam abuse.
    You could investigate the IP addresses these orders were place from, and perhaps ban them.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Oct 2004
    Posts
    20
    Plugin Contributions
    0

    Default Re: Site hacked?

    This is the e-mail the lady sent me,

    "Hello. I'm really upset...Last night I created an account with you to download a couple of your freebies and possibly order a kit or two (which I was going to do this morning). To my surprise, this morning I woke up to an inbox full of order confirmations for orders that I did not place (10 in total). My security has been compromised! There are now a bunch of people that have my personal information...my full name, phone number, address and e-mail. Thank goodness I hadn't purchesed anything or they'd have that information too! Words cannot describe how violated I feel. You truly need
    to do something to fix this situation."

    I wasn't sure if this was the "hacker" still trying to get information from me by my reply.

  4. #4
    Join Date
    Jan 2004
    Posts
    66,444
    Plugin Contributions
    279

    Default Re: Site hacked?

    This isn't hacking.

    This is most likely a result of advertising a URL to your site which included a &zenid=xxxxxxxxxxxxxxxxxxxx section in the link.

    This would allow anybody to take over someone else's session if both people came in via that same link.

    Try turning "Recreate Session" "on" in Admin->Configuration->Sessions
    This should help prevent that behaviour.

    However, you need to TEST several purchases from several different computers to be sure things are still working right.

    AND ... GO FIND THAT BAD PUBLISHED URL ... and get rid of it...
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    Oct 2004
    Posts
    20
    Plugin Contributions
    0

    Default Re: Site hacked?

    I'll try that--as soon as I can. The server is flaky today! I'll update as soon as I do this.

    Thank you!

  6. #6
    Join Date
    Oct 2004
    Posts
    20
    Plugin Contributions
    0

    Default Re: Site hacked?

    In looking at the orders, I see two IP addresses for each order, on right after the other. This particular lady does have her IP address on several of the orders as the first IP address, but the second ones differ. And then there are orders with two completely different IPs. How do I figure out if I should ban any?

    Sorry so many questions--I'm really new to all this!

  7. #7
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: Site hacked?

    you dont need to ban any of these,
    you need to findout where the link was that they came in from,
    Also re-assure her that even had she placed an order that none of her payment information is stored,
    Zen cart PCI compliant Hosting

  8. #8
    Join Date
    Oct 2004
    Posts
    20
    Plugin Contributions
    0

    Default Re: Site hacked?

    Is there any easy way of tracking that? I have people that post links to the store, gallery, forums all over the place!

    And any way to prevent that happening again or will the Recreating Sessions work?

  9. #9
    Join Date
    Jan 2004
    Location
    N of San Antonio TX
    Posts
    9,691
    Plugin Contributions
    11

    Default Re: Site hacked?

    Quote Originally Posted by DrByte
    This isn't hacking.

    This is most likely a result of advertising a URL to your site which included a &zenid=xxxxxxxxxxxxxxxxxxxx section in the link.

    This would allow anybody to take over someone else's session if both people came in via that same link.

    Try turning "Recreate Session" "on" in Admin->Configuration->Sessions
    This should help prevent that behaviour.

    However, you need to TEST several purchases from several different computers to be sure things are still working right.

    AND ... GO FIND THAT BAD PUBLISHED URL ... and get rid of it...


    Do a search through your site to find "&zenid". You, or someone "helping" you, has added a link AND added the Zen ID into it. When this is done, everyone who clicks the link is entered into the same session and one order places an order for everyone including those who did not log out and whose session has not dropped.

    Most of them are on the main page inserted from the define pages editor but, there may be others.
    A little help with colors.
    myZenCartHost.com - Zen Cart Certified, PCI Compatible Hosting by JEANDRET
    Free SSL & Domain with semi-annual and longer hosting. Updating 1.5.2 and Up.

  10. #10
    Join Date
    Oct 2004
    Posts
    20
    Plugin Contributions
    0

    Default Re: Site hacked?

    That seemed to work . . . only now the whole center section of the store has disappeared!
    I checked all the settings I know about from Admin and everything is turned on that needs to be but my main page info., New Products, Specials, and when you click on a product the descriptions are no longer there!

    Can someone help? http://liddysloft.com/boutique/index.php?main_page=index

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. ZenID problem vs SSU
    By Nintendoparts in forum Basic Configuration
    Replies: 0
    Last Post: 26 Oct 2010, 11:11 AM
  2. Strange Zenid problem
    By Aletiger in forum Installing on a Windows Server
    Replies: 9
    Last Post: 6 Aug 2010, 09:37 AM
  3. zenid problem??
    By Shane78 in forum General Questions
    Replies: 3
    Last Post: 22 Nov 2009, 06:04 PM
  4. Replies: 5
    Last Post: 6 Apr 2008, 01:57 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg