Zen Cart Logo
Forums / Reports of Security Problems / http://www.milw0rm.com/exploits/9004

http://www.milw0rm.com/exploits/9004

Views: 22

Results 1 to 3 of 3
5 Jan 2010, 10:24 PM
#1
timdwyer42 avatar

timdwyer42

Zen Follower

Join Date:
Apr 2009
Posts:
149
Plugin Contributions:
0

http://www.milw0rm.com/exploits/9004

Hello I'm just wondering is this a serious exploit and has it been "fixed"?

http://www.milw0rm.com/exploits/9004

I do get urls in the whos online line

index.php?main_page//wp-comments.php

ect.

I have applied the security patches and changed my admin location.

Perhaps one of the mods could pm me and let me know is this not an issue if the security patches are applied?

Thanks.

6 Jan 2010, 2:00 AM
#2
drbyte avatar

drbyte

Sensei

Join Date:
Jan 2004
Posts:
63,513
Plugin Contributions:
177

Re: http://www.milw0rm.com/exploits/9004

timdwyer42:

Hello I'm just wondering is this a serious exploit and has it been "fixed"?

http://www.milw0rm.com/exploits/9004That's what this Admin Security Patch was designed to address: http://www.zen-cart.com/forum/showthread.php?t=130161

timdwyer42:

I do get urls in the whos online line

index.php?main_page//wp-comments.php

ect.
The whos-online is merely telling you what visitors are attempting to visit.
It's not uncommon for newbie hackers to poke around looking for potential exploits. You'll see that activity in your logs. It doesn't mean they're successful ... or not.
If you're concerned that they're doing something rogue, you should check what happens when visiting that URL yourself. If you've properly protected yourself and your site is clean and not hacked, you should expect to be directed to a legitimate Zen Cart page.
And ... if you're unsure whether you've been hacked, you need to do a thorough inspection of your site, treating it just as if you have been hacked, until you can prove to yourself otherwise.

19 Jan 2010, 11:57 AM
#3
timdwyer42 avatar

timdwyer42

Zen Follower

Join Date:
Apr 2009
Posts:
149
Plugin Contributions:
0

Re: http://www.milw0rm.com/exploits/9004

Thanks. Yes just the normal page shows up when I click the actual urls. Is there anyway just to block them totally? As there are up to 200 urls of these on the who is online at any one time.