Zen Follower
- Join Date:
- Aug 2005
- Location:
- New York!!!
- Posts:
- 141
- Plugin Contributions:
- 0
Possible Click Jacking/XSS scripts
Hello,
I want to forward you the files to take a look (they are zipped) but I can not upload them and attach them here in the forum because they are too large in size, so if someone can reply with an email I can mail it.
First, I am not sure how the hacker got into our system (we are still pouring through some logs here), but we did find extra files that suddenly showed up. On Kaspersky Antivirus, we kept getting messages that our website was infected with Exploit Black hole Exploit Kit (Type 2724). Now, what my users were seeing is every once in a while was a bit different than the typical black hole exploit, they would be surfing our website and click on a link and it would redirect 2-3 times typically to adultfriendfinder.com
Now this redirection typically would only happen 1 time a day per user or IP address and it was very sporadic and it was happening on our website for quite some time. We finally went through all the files and found that the editors folder had extra files in it with some odd scripts. Typically when we look for scripts or iframes placed in Zen cart we use the developer's tool kit and search for those keywords (script, iframe, base_64, etc....), well those keywords were not coming up when we were searching. So anyways, I am going to send the file for you to look at since this seems to be effecting other version 1.5 Zen carts as well according to Kaspersky.
If you have any questions please feel free to ask. The website is https://www.trinorthlighting.com/Store and it should be clean now. My contact number is 716-672-9833 if you would like to speak (Sometimes it's easier to ask questions via phone than type.)
Jeff