Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

HIDDEN HACKING CODE IN MY WEBSTORE PLEASE HELP


agnes

Recommended Posts

Posted

Hi

 

Can anyone help me please. Some rotten so and so has placed about 100 links for viagra in my webstore. I have spent many hours in cpanel file manager trying to find the html pages and have removed about 80 links.

 

I am now stuck as I simply cannot locate the rest.

 

Can you see the location by looking at the source?

 

www.memoriesforeveruk.co.uk/webstore

 

it is above my logo and appears on every page.

 

I have changed my password to hopefully prevent anymore attacks.

 

Do you know where I can get security updates from on this website?

 

Very many thanks for reading and hopfully helping me out!

 

Thank you and merry christmas

 

Agnes UK

Posted

Try looking in webstore/index.php

 

There might be an include statement that includes code that displays these lines.

 

Also you could download a copy of the entire site to your pc and use windows explorer to search for viaga in all the files you download.

Need help installing add ons/contributions, cleaning a hacked site or a bespoke development, check my profile

 

Virus Threat Scanner

My Contributions

Basic install answers.

Click here for Contributions / Add Ons.

UK your site.

Site Move.

Basic design info.

 

For links mentioned in old answers that are no longer here follow this link Useful Threads.

 

If this post was useful, click the Like This button over there ======>>>>>.

Posted

I may have found some of what you're looking for.

 

In this folder: /webstore/images/imagecache

 

Check these files:

 

17538.php

29858.php

 

If I find more, I'll post again.

If I suggest you edit any file(s) make a backup first - I'm not perfect and neither are you.

 

"Given enough impetus a parallelogramatically shaped projectile can egress a circular orifice."

- Me -

 

"Headers already sent" - The definitive help

 

"Cannot redeclare ..." - How to find/fix it

 

SSL Implementation Help

 

Like this post? "Like" it again over there >

Posted

In this folder: /webstore/images

 

Check these:

 

216278.php

225289.php

If I suggest you edit any file(s) make a backup first - I'm not perfect and neither are you.

 

"Given enough impetus a parallelogramatically shaped projectile can egress a circular orifice."

- Me -

 

"Headers already sent" - The definitive help

 

"Cannot redeclare ..." - How to find/fix it

 

SSL Implementation Help

 

Like this post? "Like" it again over there >

Posted
I may have found some of what you're looking for.

 

In this folder: /webstore/images/imagecache

 

Check these files:

 

17538.php

29858.php

 

If I find more, I'll post again.

 

Many thanks Jim, I have removed them, but still have the viagra links on webstore!

 

Regards

 

Agnes UK

Posted
In this folder: /webstore/images

 

Check these:

 

216278.php

225289.php

 

Many thanks Jim, I have removed them, but I still have the viagra links on webstore! Arrrrgghhhhh!!!!!

 

Regards

 

Agnes UK

Posted
Many thanks Jim, I have removed them, but I still have the viagra links on webstore! Arrrrgghhhhh!!!!!

 

Regards

 

Agnes UK

 

have you checked your header file? The code may be sitting in there

Regards

 

Mark A Reynolds

Posted

I'd agree with the last post.

 

They either hacked every single page, or a module that all the pages use.

 

All the pages use your /webstore/includes/header.php and /webstore/includes/application_top.php

 

If you're not sure, post the contents of both of those files.

 

There are many qualified eyes here that can spot rogue code in a heartbeat.

;)

If I suggest you edit any file(s) make a backup first - I'm not perfect and neither are you.

 

"Given enough impetus a parallelogramatically shaped projectile can egress a circular orifice."

- Me -

 

"Headers already sent" - The definitive help

 

"Cannot redeclare ..." - How to find/fix it

 

SSL Implementation Help

 

Like this post? "Like" it again over there >

Posted
have you checked your header file? The code may be sitting in there

 

TOP MAN!!!!!

 

Mark many thanks indeed, it's very nice to know that genuine people still exist!

 

It was in the review_php pages and goodness knows where else.

 

You are a real gent.

 

Thanks and remember to look me up when you are this way, I will take you for a run in the old car.

 

Cheers

 

Garry & Agnes

Posted
I'd agree with the last post.

 

They either hacked every single page, or a module that all the pages use.

 

All the pages use your /webstore/includes/header.php and /webstore/includes/application_top.php

 

If you're not sure, post the contents of both of those files.

 

There are many qualified eyes here that can spot rogue code in a heartbeat.

;)

 

Thanks Jim, Mark has now sorted it all out. I am downloading a clean site now in my dreamweaver CS3 and will be able to back up / restore from that if these low lifes do it again. What do they get out of this, I wonder what happens if you make contact with the link end? Best not go there I guess!

 

low lifes anyway....

 

I have broken the link where the reviews normally show but I am ok with that. I may even see if I can edit out the review button on ecah product anyway.

 

Cheers

 

Garry & Agnes

Posted
I have broken the link where the reviews normally show but I am ok with that. I may even see if I can edit out the review button on ecah product anyway

 

Not any more ;)

Regards

 

Mark A Reynolds

Posted

You may want to check permissions on your files/folders to try to stop this from happening again.

 

According to my "source", in osC folders should be 755 and files 644

If I suggest you edit any file(s) make a backup first - I'm not perfect and neither are you.

 

"Given enough impetus a parallelogramatically shaped projectile can egress a circular orifice."

- Me -

 

"Headers already sent" - The definitive help

 

"Cannot redeclare ..." - How to find/fix it

 

SSL Implementation Help

 

Like this post? "Like" it again over there >

Posted
You may want to check permissions on your files/folders to try to stop this from happening again.

 

According to my "source", in osC folders should be 755 and files 644

 

Your right Jim - He has been advised and he should be doing it as we speak

 

Thanks

 

Mark

Regards

 

Mark A Reynolds

Posted

Another form of defense is to keep "prying eyes" out of places they don't belong....

 

Like here:

 

Click me

 

In that folder, and other folders people can reach from their browser that they don't need access to, make a file called "index.php" with this code in it:

 

<?php
header ("Location: http://memoriesforeveruk.co.uk/webstore/index.php");
?>

Then, if they go there, it pops them right into the main page on the site.

 

Just be sure you NEVER overwrite an existing index.php file!!!

 

My theory is they can't hack what they can't see...

:thumbsup:

If I suggest you edit any file(s) make a backup first - I'm not perfect and neither are you.

 

"Given enough impetus a parallelogramatically shaped projectile can egress a circular orifice."

- Me -

 

"Headers already sent" - The definitive help

 

"Cannot redeclare ..." - How to find/fix it

 

SSL Implementation Help

 

Like this post? "Like" it again over there >

Posted
Another form of defense is to keep "prying eyes" out of places they don't belong....

 

Like here:

 

Click me

 

In that folder, and other folders people can reach from their browser that they don't need access to, make a file called "index.php" with this code in it:

 

<?php
header ("Location: http://memoriesforeveruk.co.uk/webstore/index.php");
?>

Then, if they go there, it pops them right into the main page on the site.

 

Just be sure you NEVER overwrite an existing index.php file!!!

 

My theory is they can't hack what they can't see...

:thumbsup:

 

Great tip :thumbsup:

Regards

 

Mark A Reynolds

Posted

Better still, for OSC, use index.html instead of index.php with this code:

 

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
<title></title>
<meta http-equiv="refresh" content="0;URL=http://MYDOMAIN.com" />
</head>
<body>
</body>
</html>

 

This way you'll never have the worry of overwriting index.php

SolarFrenzy

Solar powered gadgets at down to earth prices.

 

CheekyNaughty

Promoting British Design

Posted

True, you'll never overwrite it.

 

But if you accidentally put it in the same folder with an index.php file, the index.html file becomes the "default" page (if someone types http://www.your_site.com/folder into their browser address bar).

 

Useful information for anyone with both an index.php and an index.html (or index.htm) in the same folder, who wonders why they can't get the PHP page to display.

If I suggest you edit any file(s) make a backup first - I'm not perfect and neither are you.

 

"Given enough impetus a parallelogramatically shaped projectile can egress a circular orifice."

- Me -

 

"Headers already sent" - The definitive help

 

"Cannot redeclare ..." - How to find/fix it

 

SSL Implementation Help

 

Like this post? "Like" it again over there >

Posted
You may want to check permissions on your files/folders to try to stop this from happening again.

 

According to my "source", in osC folders should be 755 and files 644

 

Hi Jim

 

755 and 644, working may way through all my files.

 

Have a good one.

 

Garry & Agnes

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...