Jump to content


Corporate Sponsors


Latest News: (loading..)

* * * * * 5 votes

Security issue with admin directory


208 replies to this topic

#201 DunWeb

  • Community Sponsor
  • 10,447 posts
  • Real Name:Chris Dunn
  • Gender:Male
  • Location:Tecumseh, Ontario, Canada N8N 1X8

Posted 26 January 2012, 14:54

oops


Chris

Edited by DunWeb, 26 January 2012, 14:54.

:|: Was this post helpful ? Click the LIKE THIS button :|:

:|: Click Here to learn how I can help you with custom coding, add ons, security and templates :|:

:|: Need an Area Calculator, Pre-Paid Account, Virtual Pin, Auction or Layaway Add on ? Click Here :|:

#202 altoid

  • Community Member
  • 536 posts
  • Real Name:Steve
  • Gender:Male
  • Location:Pennsylvania

Posted 26 January 2012, 17:15

View Postski holidays, on 26 January 2012, 14:05, said:

Hi All, my installation of Oscommerce RC2.2 was hacked even though I renamed admin folder and applied htaccess. Does anybody know if any other possible vulnerability that could of allowed the hackers in?

Hello there, for the 2.2 Osc there's a bunch of securty recommendations. See the very first post in this topic by Jan; he provides info there on more security measures.
I am not a professional webmaster or PHP coder by background or training but I will try to help as best I can.
I remember what it was like when I first started with osC. It can be overwhelming.
However, I strongly recommend considering hiring a professional for extensive site modifications, site cleaning, etc.
There are several good pros here on osCommerce. Look around, you'll figure out who they are.

#203 ski holidays

  • Community Member
  • 2 posts
  • Real Name:Brandon kane
  • Gender:Male
  • Location:London

Posted 27 January 2012, 11:01

D'Oh, I missed that. Thanks I will look that up. I read your signature, feels like I am at the beginning of the journey that you took, sheesh!

#204 Taipo

  • Community Member
  • 751 posts
  • Real Name:Te Taipo
  • Gender:Male

Posted 27 January 2012, 18:59

There is a known security issue with the 2.2 range of osCommerce versions that offer an admin login. It is possible that attackers were able to add rogue shell files into your sites directories, often in the images directory, which are used to exploit your website. So along with following the security recommendations here, make sure you go through all your website directories and remove any php files that should not be there.
- Stop Oscommerce hacks dead in their tracks with osC_Sec (see discussion here)
- Another discussion about infected files ::here::
- A discussion on file permissions ::here::
- Site hacked? Should you upgrade or not, some thoughts ::here::
- Ignore this link - just a honeypot site to test my ideas out for osC_Sec and allow the site to be picked up by attackers.
- Fix the admin login bypass exploit here

#205 vampirehunter

  • Community Member
  • 31 posts
  • Real Name:vampire

Posted 11 April 2012, 20:59

Hi
can someone point me to the definitive list of things I should do to secure a brand new 2.3.1 installation?

which addons, things i should change?

i Tried oscommerce about 4 years back but that table layout almost made me kill myself. I see that the new version is CSS ready, so hopefully I can try again, but the contributions thing is also a problem.

I found it really annoying going through all them coded files replacing so many bits, i hope i don't have to do so many again
Please advise of the 2.3.1 security procedures to make it strong and safe from hackers.

thanks

#206 DunWeb

  • Community Sponsor
  • 10,447 posts
  • Real Name:Chris Dunn
  • Gender:Male
  • Location:Tecumseh, Ontario, Canada N8N 1X8

Posted 11 April 2012, 21:06

@vampirehunter

There are no known security issues with v2.3.1, however there are some additional measures that you can take to monitor your installation. Read this thread: http://forums.oscommerce.com/topic/375288-updated-security-thread/page__hl__security%20231

Also, the installation of contributions has not changed, there are still manual code edits when applying changes.


Chris
:|: Was this post helpful ? Click the LIKE THIS button :|:

:|: Click Here to learn how I can help you with custom coding, add ons, security and templates :|:

:|: Need an Area Calculator, Pre-Paid Account, Virtual Pin, Auction or Layaway Add on ? Click Here :|:

#207 vampirehunter

  • Community Member
  • 31 posts
  • Real Name:vampire

Posted 11 April 2012, 21:13

View PostDunWeb, on 11 April 2012, 21:06, said:

@vampirehunter

There are no known security issues with v2.3.1, however there are some additional measures that you can take to monitor your installation. Read this thread: http://forums.oscommerce.com/topic/375288-updated-security-thread/page__hl__security%20231

Also, the installation of contributions has not changed, there are still manual code edits when applying changes.


Chris

ok thanks

i read the page, it says for the ones in 2.31 i should install these particular ones? is this right?

1. Security Pro from FWR Media {
2.3.1 and lower.
a. Addon
b. Support
}


3. Filesafe from FWR Media {
2.3.1 and lower
a. Addon
b. Support
Filesafe replaces "Site Monitor". Site Monitor is old and tired.
}



5. Rename /admin/ and htpasswd it {
2.3.1 and lower
a. if your admin area is located at /admin/ change it now by renaming it to something randomly hard to guess, eg: /d9fne3ufvurjes%kep/
b. amend the file /includes/configure.php (in the newly renamed admin area) to reflect the new name (it should be very obvious where to amend that file!)
}

6. Remove references to (newly renamed) admin area in outgoing emails {
2.3.1 and lower
a. renaming your admin area is great, but it is still possible to find out where it is, by placing an order, as outgoing emails contain the admin address. More.
}

7. Add extra login parameter (JanZ) {
2.3.1 and lower
a. link - scroll down to "admin/includes/application_top.php Line 146-151" and start reading.
}

#208 Taipo

  • Community Member
  • 751 posts
  • Real Name:Te Taipo
  • Gender:Male

Posted 13 April 2012, 22:16

Its all optional for version 2.3.1

So far there has been no known security holes found in that version. The 2.2 range of osCommerce sites though need addition code patches.
- Stop Oscommerce hacks dead in their tracks with osC_Sec (see discussion here)
- Another discussion about infected files ::here::
- A discussion on file permissions ::here::
- Site hacked? Should you upgrade or not, some thoughts ::here::
- Ignore this link - just a honeypot site to test my ideas out for osC_Sec and allow the site to be picked up by attackers.
- Fix the admin login bypass exploit here

#209 spooks

  • Community Member
  • 7,017 posts
  • Real Name:Sam
  • Gender:Male
  • Location:UK

Posted 13 April 2012, 22:44

Quote

6. Remove references to (newly renamed) admin area in outgoing emails {

The fix you linked to often no longer works, see my post in the linked thread
Sam

Remember, What you think I ment may not be what I thought I ment when I said it.

Contributions:


Auto Backup your Database, Easy way

Multi Images with Fancy Pop-ups, Easy way

Products in columns with multi buy etc etc

Disable any Category or Product, Easy way

Secure & Improve your account pages et al.