Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

Security alert


Juto

Recommended Posts

Hi!

 

I was googling after some other things, when I found these two sites with hackers scripts.

 

The first is in Spanish, the second in English:

1)

http://foro.elhacker.net/nivel_web/multipl...-t258462.0.html

2)
http://www.dnstheplanet.com/

 

I do not understand Spanish, so maby someone could translate? I tried googles translate, but it came out as garbage.

 

The second is using a flaw in admin's "who's online".

 

It seems to me that the hackers have coding skills well above the avarage oscommerce users.

 

 

Sara

Link to comment
Share on other sites

The second is using a flaw in admin's "who's online".

 

It seems to me that the hackers have coding skills well above the avarage oscommerce users.

 

 

The 2nd isnt really a hack, all thats happening is that who's online will show the wrong ip when they visit after they change their browser setup, their not getting into anything!!

Sam

 

Remember, What you think I ment may not be what I thought I ment when I said it.

 

Contributions:

 

Auto Backup your Database, Easy way

 

Multi Images with Fancy Pop-ups, Easy way

 

Products in columns with multi buy etc etc

 

Disable any Category or Product, Easy way

 

Secure & Improve your account pages et al.

Link to comment
Share on other sites

  • 3 weeks later...

The Spanish post consisted of 2 vulnerabilities (with a POC exploit!).

 

Both attacks are easily stopped by renaming the admin and password protecting the directory.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...