Zen Cart Logo
Forums / Reports of Security Problems / yet another CC module hack attempt

yet another CC module hack attempt

Locked

Views: 10

Results 1 to 2 of 2
This thread is locked. New replies are disabled.
08 Nov 2009, 16:09
#1
ksolito avatar

ksolito

New Zenner

Join Date:
Nov 2006
Posts:
44
Plugin Contributions:
0

yet another CC module hack attempt

I had two customers get hacked in the last few days. They are somehow getting in and replacing the middle digit email address with another that is similar but visually different. The second attempt added a second email address followed by a comma.

First store:
replaced something like johnsmith###################### with johnsmith##################.

Second store:
johnsmith###################### with johnsmith######################,johsmith######################.

An error email was sent to the admin after that and the middle CC#s were not recorded for the couple sales made before I found out and changed it back. I confirmed this (order placed but no middled digits saved to db) by testing it myself but I have no way to be sure the CC#s weren't compromised.

Both stores are v1.3.8a. Directories are 755 and files are all 644 in both.

Both are hosted by the same company on shared servers though I don't know that they are physically on the same servers.

This has been an ongoing struggle to keep ZC from these sort of hacks. They also happen on a 2004ish Oscommerce site I work on. (owners refuse to upgrade)

Minimally, I am going to recommend a change to authorize.net but the repeated hacks, successful or not, are making me question whether Zen Cart can be sufficiently secured to prevent periodic hack attempts.

Any insight is greatly appreciated.

08 Nov 2009, 18:56
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
177

Re: yet another CC module hack attempt

In June 2009, all forum members were emailed about an important security patch to protect your admin area.
http://www.zen-cart.com/forum/showthread.php?t=130161
Sounds like you've been hacked because you weren't protected. Now you'll need to patch and do all the requisite cleanup.