New Zenner
- Join Date:
- Dec 2008
- Posts:
- 45
- Plugin Contributions:
- 0
Recently Hacked / Attacked Sites
I currently am running 4 sites with ZC 1.3.8.a, one of which is live and has several add-ons, two of which are currently being worked on, and the last which is a demo of the initial install.
I recently started having a spike (1000%) in my dedicated server's bandwidth which prompted GoDaddy's techs to look into malware installed on my server.
This is the reply I received today:
"We have reviewed your server and found that you are running multiple versions of Zen Cart which are vulnerable to an attack which bypasses security restrictions. This allowed the attacker to upload attack shells to the site. The security department has removed the most obvious attack shells from all of the Zen Cart image directories but we can't guarantee that they were all removed. It is recommended that you review all of your site content and update the installations for Zen Cart to the latest version including all applicable security patches. It appears that this may date back as far as Aug 2009."
They have not yet identified which sites were attacked, but the two sites under construction were installed around the time they are suggesting the problem began. Please advise or direct me to prevent this from happening again.
Please let me know if you need a list of the add-ons installed on each. All sites modified are modified using the overrides folders method.
Thanks,
AC