Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

Vulnerability or hack?


MANDY1

Recommended Posts

Good morning to all,

 

In recent days I have been seeing page connexions like this in my whos on line screen (I have of course replaced my real domaine name by MYDOMAINE but the rest is exactly as seen :

 

http://www.MYDOMAINE.com/index.php?languag...46;/proc/self/e

 

My file permissions are all not writeable, I have examined the index file but not found hidden text. I am using Mysql5 with PHP 4.1.3, osc2.2ms2-060817 updated. Contribs Header Tags SEO, Ultimate SEO (Chemo's).

 

What is this and how to counter it?

 

Thank you in advance.

 

Mandy

Link to comment
Share on other sites

Check all your files & look for added ones, esp in images folder

 

Check your site logs in cPanel, error logs will often show hacking attempts. Also look in stats for frequent visitors.

 

http://www.oscommerce.com/forums/index.php?showtopic=313323

Sam

 

Remember, What you think I ment may not be what I thought I ment when I said it.

 

Contributions:

 

Auto Backup your Database, Easy way

 

Multi Images with Fancy Pop-ups, Easy way

 

Products in columns with multi buy etc etc

 

Disable any Category or Product, Easy way

 

Secure & Improve your account pages et al.

Link to comment
Share on other sites

Check all your files & look for added ones, esp in images folder

 

Check your site logs in cPanel, error logs will often show hacking attempts. Also look in stats for frequent visitors.

 

http://www.oscommerce.com/forums/index.php?showtopic=313323

 

 

Hello Sam,

 

I have checked all files and there is absolutely nothing new (site monitor shows no changes) and I have User Tracking and the IP addresses with these are all different. I have tried to install Security Pro and the cross script contrib but with the htaccess modified for Ultimate SEO I am not sur how or where to include other changes. This doesn't seem to pass by images but rather the index, languages (I have 2 and it is apparently only used on the English call. Where is my vulnerablity and what does this particular thing look for? Any ideas?

 

Mandy

Link to comment
Share on other sites

Perhaps its just hacking probes, you havent given enough info for any better diagnosis.

 

If you add the htaccess file given to the root, any htaccess in deeper directories will take presidence.

Sam

 

Remember, What you think I ment may not be what I thought I ment when I said it.

 

Contributions:

 

Auto Backup your Database, Easy way

 

Multi Images with Fancy Pop-ups, Easy way

 

Products in columns with multi buy etc etc

 

Disable any Category or Product, Easy way

 

Secure & Improve your account pages et al.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...