Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

osCommerce question (not the usual sort)

  • 30-09-2007 9:12pm
    #1
    Banned (with Prison Access) Posts: 8,486 ✭✭✭


    Have been using osCommerce for years and have never come across this:

    today while ironing out the finishing touces to a store for a client today I made a test purchase and low and behold when I go into the admin section to view the order theres about 20 spam orders for Dell Inspirons and Viagra etc basically a load of stuff the site doesnt sell.

    Has anyone here every come across this before because I certainly haven't ? Everything is secured on the site as well which is perplexing me?


Comments

  • Registered Users, Registered Users 2 Posts: 3,594 ✭✭✭forbairt


    miju wrote:
    Have been using osCommerce for years and have never come across this:

    today while ironing out the finishing touces to a store for a client today I made a test purchase and low and behold when I go into the admin section to view the order theres about 20 spam orders for Dell Inspirons and Viagra etc basically a load of stuff the site doesnt sell.

    Has anyone here every come across this before because I certainly haven't ? Everything is secured on the site as well which is perplexing me?

    Haven't come across that before ... did you have anyone testing out the site ? someone trying some kinda injection attack on the system ?


  • Registered Users, Registered Users 2 Posts: 7,740 ✭✭✭mneylon


    Was there a demo user or demo data at some point?


  • Registered Users, Registered Users 2 Posts: 1,262 ✭✭✭di11on


    Silly question... but I presume your admin area is password protected?

    Have you deleted the install directory?


  • Banned (with Prison Access) Posts: 8,486 ✭✭✭miju


    blacknight wrote:
    Was there a demo user or demo data at some point?

    there wasn't actually as i just happened to decide to delete it when i installed osCommerce (normally wouldn't though)
    di11on wrote:
    Silly question... but I presume your admin area is password protected?

    Have you deleted the install directory?

    yep everything install related is deleted and admin area is renamed and password protected with .htaccess with a 8 number / character password

    have to say am very perplexed by it


  • Closed Accounts Posts: 17 WPI20000


    MAke your password really hard to guess


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 1,262 ✭✭✭di11on


    miju wrote:
    .... and 8 number / character password ...

    I'd say that wuold be hard to guess!


  • Registered Users, Registered Users 2 Posts: 1,530 ✭✭✭CptSternn


    Do you have access to your web logs? I would definately look to see where that came from. I have seen similar issues with other shopping cart software - backdoors or bugs that can be accessed via the web (or automated via script).

    If I were you I would find those logs and see exactly what they did to inject those records into your system, else you may find they are able to cause havok later if they perfect the technique.


  • Banned (with Prison Access) Posts: 8,486 ✭✭✭miju


    well actually i think it is it'd look something like 9PaSwORD9 (not the actual password - use 2 instead :) )


Advertisement