Zen Cart Logo
Forums / Reports of Security Problems / Customer resend password vulnerability?

Customer resend password vulnerability?

Views: 60

Results 1 to 1 of 1
17 Aug 2012, 12:49
#1
skelly100 avatar

skelly100

New Zenner

Join Date:
Nov 2009
Posts:
34
Plugin Contributions:
0

Customer resend password vulnerability?

Ver 1.50
mods - lightbox,flex attributes
template - all business

Hi there,

tried to login to my admin last night but couldn't.

Tried 'forgot password' and got an 'enter your email address' field (is this correct, surely just send to admins address?) no new password email was recieved.

Ran the reset password script in mypyp and gained access to my admin area where i found a new admin user had been created, which I deleted.

Contacted hosting (UK2) who just sent the usual 'scan your PC for viruses nonsense'
I was suspicious that it was at the server level as I have a .htaccess file in my admin folder (renamed of course) to deny from all except my IP.

Looking through my server logs for around the time this had happened the only suspicious activity I
could find was someone/thing on the reset a customers account login password page (non-existant customer of course)

Were they trying/succeeding in launching a script from here?

I ran winmerge against a stored copy of files and could not see any extra code had been inserted into
any PHP files or images folder.

Any help would be appreciated.

Keep up the great work!

Kind Regards

SK