Zen Cart Logo
Forums / Reports of Security Problems / Possible Click Jacking/XSS scripts

Possible Click Jacking/XSS scripts

Views: 23

Results 1 to 4 of 4
01 Aug 2013, 14:07
#1
trinorthlighting avatar

trinorthlighting

Zen Follower

Join Date:
Aug 2005
Location:
New York!!!
Posts:
141
Plugin Contributions:
0

Possible Click Jacking/XSS scripts

Hello,

I want to forward you the files to take a look (they are zipped) but I can not upload them and attach them here in the forum because they are too large in size, so if someone can reply with an email I can mail it.

First, I am not sure how the hacker got into our system (we are still pouring through some logs here), but we did find extra files that suddenly showed up. On Kaspersky Antivirus, we kept getting messages that our website was infected with Exploit Black hole Exploit Kit (Type 2724). Now, what my users were seeing is every once in a while was a bit different than the typical black hole exploit, they would be surfing our website and click on a link and it would redirect 2-3 times typically to adultfriendfinder.com

Now this redirection typically would only happen 1 time a day per user or IP address and it was very sporadic and it was happening on our website for quite some time. We finally went through all the files and found that the editors folder had extra files in it with some odd scripts. Typically when we look for scripts or iframes placed in Zen cart we use the developer's tool kit and search for those keywords (script, iframe, base_64, etc....), well those keywords were not coming up when we were searching. So anyways, I am going to send the file for you to look at since this seems to be effecting other version 1.5 Zen carts as well according to Kaspersky.

If you have any questions please feel free to ask. The website is https://www.trinorthlighting.com/Store and it should be clean now. My contact number is 716-672-9833 if you would like to speak (Sometimes it's easier to ask questions via phone than type.)

Jeff

01 Aug 2013, 15:51
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
177

Re: Possible Click Jacking/XSS scripts

If you have proof-of-concept details showing that your exploit came from Zen Cart code, please email them to [email protected]

If your vulnerability was in your editor plugin, best to report that editor's vulnerability to that editor's security team.

01 Aug 2013, 16:43
#3
trinorthlighting avatar

trinorthlighting

Zen Follower

Join Date:
Aug 2005
Location:
New York!!!
Posts:
141
Plugin Contributions:
0

Re: Possible Click Jacking/XSS scripts

Hi,
We still have not verified how they got in yet, maybe once you look at it we can do a bit of backtracking. The files that were inserted were wrote for zen cart specifically and they may somehow point to infected zen files. One worry that I have is that we are comparing sizes of files and if the hacker is very smart, they can edit infected files to be the same size in kb and also spoof the date coding. I will be emailing them from [email protected] to you. This one is very stealthy and deserves a good look at.

Jeff

02 Aug 2013, 01:03
#4
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
177

Re: Possible Click Jacking/XSS scripts

After a cursory review of the shell script you shared, it appears to be highly generic, as in it's got code in it to exploit all kinds of software.
A google search about it suggests that Wordpress is a common entry point used to put the script onto servers.

Might want to look into every account/site on the server that has Wordpress installed on it.