Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

.exe hack


Henry Blake

Recommended Posts

Hi Everyone

 

Today I went onto my site and got a .exe type virus this made it impossible to run any .exe files on my computer.

 

Nightmare!

 

Anyway I easily got rid of it. But I got a call from a customer saying they had the same problem.

 

I have a couple of thoughts on where this came from.

 

1. I considered that it may have been from the email link in order confirmation linking back to the customers account. He had used this link this morning and then got the virus. So i deleted the email link back to customers account.

 

2. I recently embedded a couple of youtube videos into the site which may have been a weak link. Does anyone have any experience of the youtube embed code being weak spots fro virus's

 

Any help or advice on this matter would be greatly appreciated.

 

Cheers

 

Henry

Link to comment
Share on other sites

You might want to have a read through the instructions on how to clean up your site and patch it against intrusion. The more likely scenario is that there is an iframe embedded in one of the pages on your site that installs a virus into your computer. Some of these viruses intentions are to grab your FTP login details, or control panel login details for later use once you patch your site.

- Stop Oscommerce hacks dead in their tracks with osC_Sec (see discussion here)
- Another discussion about infected files ::here::
- A discussion on file permissions ::here::
- Site hacked? Should you upgrade or not, some thoughts ::here::
- Fix the admin login bypass exploit here
- Pareto Security: New security addon I am developing, a remake of osC_Sec in PHP 5 with a number of fixes
- BTC:1LHiMXedmtyq4wcYLedk9i9gkk8A8Hk7qX

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...