hacked i would guess
#-19
Posted 22 September 2010 - 02:45 PM
anywyas on to the reason for my problem... when you try and go to my store now (it was fine for about a month) it freeks out and says there is malicious software on it or something liek that...
i know this problem has been addressed it would be easier if someone would put it in terms like the install precedures so i could fix it. or can someone PM me who would be interested to fixing this for me... :S
i knowi will get a lil abuse for being such a noob. but i thought i would ask anyways.
cheers
John
#-18
Posted 22 September 2010 - 04:23 PM
You will need to clean out the malicious code and files and then use webmaster tools to submit the clean site to google for re-evaluation.
Look for any files that are NOT part of the standard osCommerce download and remove them. Then, check each osCommerce file for scripts and code that redirect your traffic off the site.
Chris
#-17
Posted 23 September 2010 - 08:18 AM
i just realised that i didnt actually post the site if anyone wanted to look at the code...
store.khouse.org.uk/
its a small christian book store any light shed would be awesome.
thanks guys
Edited by Jan Zonjee, 03 October 2010 - 07:28 AM.
#-16
Posted 23 September 2010 - 10:48 AM
gogle_analist_3d6fa6465727d.php
goog1e1e9163b3ca51bb.php
goog1e40b95b3736ac6e.php
goog1e663023271039ca.php
goog1e72c0c885c9b967.php
goog1e_analist_3d6fa6465727d.php
goog1e_analist_698dbc436d8728.php
google_analist_3d6fa6465727d.php
google_analist_d8ed379f4d946043ceb12458dfc393ac.php
There are probably similarly named hack files in the images folder.
You're suffering from the "admin vulnerablility" hack.
Rename it and secure it with a .htaccess file
"Given enough impetus a parallelogramatically shaped projectile can egress a circular orifice."
- Me -
"Headers already sent" - The definitive help
"Cannot redeclare ..." - How to find/fix it
SSL Implementation Help
Like this post? "Like" it again over there >
#-15
Posted 03 October 2010 - 04:49 AM
I can see your site is now on the 'Attack Site' List. You need to clean it and then re-submit it for indexing so you are removed from that list.
Chris
#-14
Posted 03 October 2010 - 11:38 AM
One is a command shell that basically lets anyone who accesses it do just about anything they want on the site (add files, delete files, modify files or the DB).
If he ever comes back I hope he sends me a PM and I'll divulge the file names (if he can't find them on his own).
"Given enough impetus a parallelogramatically shaped projectile can egress a circular orifice."
- Me -
"Headers already sent" - The definitive help
"Cannot redeclare ..." - How to find/fix it
SSL Implementation Help
Like this post? "Like" it again over there >
#-13
Posted 05 October 2010 - 09:37 AM
germ, on 03 October 2010 - 11:38 AM, said:
One is a command shell that basically lets anyone who accesses it do just about anything they want on the site (add files, delete files, modify files or the DB).
If he ever comes back I hope he sends me a PM and I'll divulge the file names (if he can't find them on his own).
REALLY!!! omg!!! yeah i am back ! alas i am not actually a web guy i just work for a charity and followed the steps on this site to get us a shop to sell stuff on... yeah any info pm'd or given woudl be REALLY awesome! or email direct to johnandrachel@matsen.co.uk if thats a better idea i dont know
cheers
#-12
Posted 07 October 2010 - 01:04 AM
I have since deleted all files from the server and have done a fresh install. Whats next?
#-11
Posted 07 October 2010 - 01:31 AM
As far as I know "stock" osC doesn't store CC info - you have to modify it to get it to do that.
To secure your site visit the link below:
How to Secure Your Site
"Given enough impetus a parallelogramatically shaped projectile can egress a circular orifice."
- Me -
"Headers already sent" - The definitive help
"Cannot redeclare ..." - How to find/fix it
SSL Implementation Help
Like this post? "Like" it again over there >
#-10
Posted 08 October 2010 - 10:20 AM
#-9
Posted 08 October 2010 - 10:50 AM
germ, on 07 October 2010 - 01:31 AM, said:
[img]http://forums.oscommerce.com/public/style_emoticons/default/ohmy.gif[/img]
As far as I know "stock" osC doesn't store CC info - you have to modify it to get it to do that.
To secure your site visit the link below:
How to Secure Your Site
unfortunately it does .... Orders table `cc_number`
recorded if someone used the test CC (not for production) module.
It records everything, which is a very dangerous thing to do!!
I hope it is removed in 2.3
Nic
#-8
Posted 08 October 2010 - 01:33 PM
FIMBLE, on 08 October 2010 - 10:50 AM, said:
recorded if someone used the test CC (not for production) module.
It records everything, which is a very dangerous thing to do!!
I hope it is removed in 2.3
Nic
Sometimes the wheels of change turn very slowly....
"Given enough impetus a parallelogramatically shaped projectile can egress a circular orifice."
- Me -
"Headers already sent" - The definitive help
"Cannot redeclare ..." - How to find/fix it
SSL Implementation Help
Like this post? "Like" it again over there >
#-7
Posted 09 October 2010 - 12:13 AM
#-6
Posted 09 October 2010 - 12:17 AM
Motive, on 09 October 2010 - 12:13 AM, said:
So the version Im on is osCommerce 2.2-MS2. Is this good or do I need to update files as I am securing? Also the hosting company I use has osCMax. Is osCMax more secure or what?
Edited by Motive, 09 October 2010 - 12:19 AM.
#-5
Posted 20 October 2010 - 05:37 PM
germ, on 23 September 2010 - 10:48 AM, said:
gogle_analist_3d6fa6465727d.php
goog1e1e9163b3ca51bb.php
goog1e40b95b3736ac6e.php
goog1e663023271039ca.php
goog1e72c0c885c9b967.php
goog1e_analist_3d6fa6465727d.php
goog1e_analist_698dbc436d8728.php
google_analist_3d6fa6465727d.php
google_analist_d8ed379f4d946043ceb12458dfc393ac.php
There are probably similarly named hack files in the images folder.
You're suffering from the "admin vulnerablility" hack.
Rename it and secure it with a .htaccess file
#-4
Posted 20 October 2010 - 05:53 PM
germ, on 23 September 2010 - 10:48 AM, said:
gogle_analist_3d6fa6465727d.php
goog1e1e9163b3ca51bb.php
goog1e40b95b3736ac6e.php
goog1e663023271039ca.php
goog1e72c0c885c9b967.php
goog1e_analist_3d6fa6465727d.php
goog1e_analist_698dbc436d8728.php
google_analist_3d6fa6465727d.php
google_analist_d8ed379f4d946043ceb12458dfc393ac.php
There are probably similarly named hack files in the images folder.
You're suffering from the "admin vulnerablility" hack.
Rename it and secure it with a .htaccess file
Hello,
I got very similar files on my website public_html and in images folder as well:
goog1e_analist_add15da98d3a
goog1e_analist_10adc48720b439
goog1e45361ec6937e93 and many more.
I deleted them, but I am worry about maybe they left somewhere on my website.
Maybe you could help me to destroy them, because sometimes when I login to my oscommerce my PC anti-virus shows "blocked trojan", so I think these files are still in my website somewhere.
Please help me.
#-3
Posted 20 October 2010 - 05:58 PM
That particular is known for adding a back door to your site, which gives them access as long as the backdoor is present. I suggest you look at each file for malicious code and remove all files that are not oscommerce files. And, above ALL else........secure your website by reading the security forums.
Chris
#-2
Posted 18 November 2010 - 04:16 AM
germ, on 23 September 2010 - 10:48 AM, said:
gogle_analist_3d6fa6465727d.php
goog1e1e9163b3ca51bb.php
goog1e40b95b3736ac6e.php
goog1e663023271039ca.php
goog1e72c0c885c9b967.php
goog1e_analist_3d6fa6465727d.php
goog1e_analist_698dbc436d8728.php
google_analist_3d6fa6465727d.php
google_analist_d8ed379f4d946043ceb12458dfc393ac.php
There are probably similarly named hack files in the images folder.
You're suffering from the "admin vulnerablility" hack.
Rename it and secure it with a .htaccess file
How do I make my .htaccess file secure? I have read about blocking certain countries but I don't know how to do that. Help!? Thanks! Also, if you could tell me which countries should be blocked. I read about Russia but don't know any others.
#-1
Posted 18 November 2010 - 03:38 PM
SonshineTN, on 18 November 2010 - 04:16 AM, said:
I have this in my .htaccess file
# secure htaccess file
<Files .htaccess>
order allow,deny
deny from all
</Files>
#
As for countries to block, you have to decide where you are indending to do business. ie Would blocking a whole country affect a signifcant number of sales.
I have found the countries most likely to host an attack are in rough order of first to last, Turkey, Ukraine, Russian Federation, China and Pakistan.
None of those countries I would imagine selling to considering my products markets.
There are a few more possibly.
#0
Posted 05 December 2010 - 02:46 PM
Wayne Weedon, on 18 November 2010 - 03:38 PM, said:
# secure htaccess file
<Files .htaccess>
order allow,deny
deny from all
</Files>
#
As for countries to block, you have to decide where you are indending to do business. ie Would blocking a whole country affect a signifcant number of sales.
I have found the countries most likely to host an attack are in rough order of first to last, Turkey, Ukraine, Russian Federation, China and Pakistan.
None of those countries I would imagine selling to considering my products markets.
There are a few more possibly.
How do I add these countries to the .htaccess for blocking? Thanks!









