Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 6th, 2010, 12:48 GMT · By

Multiple osCommerce Websites Infected with Malicious Code

SHARE:

Adjust text size:


osCommerce websites injected with malicious script
Enlarge picture
Security researchers warn that multiple osCommerce websites have been compromised during the last few days. The rogue code injected into their pages attempts to infect visitors with malware served from an external domain.

The compromises have been detected by Sucuri Security, a company selling Website integrity monitoring solutions. An investigation into the incidents is ongoing, but it has been determined that all have been injected with a rogue <script> element loading code from an http://nt02. co.in/ 3 address [intentionally malformed].

So far most of the affected websites also had clandestine files uploaded in their /images folder. These files are called inclasses.php, loadclasses.php or phpclasses.php. "If you are an osCommerce user, please make sure to update your installation (and check your sites) as soon as possible," Sucuri researcher David Dede, advises.

The company is still trying to determine how the attackers succeeded in compromising the websites, but an osCommerce Remote File Injection (RFI) vulnerability disclosed about a month ago, might be responsible. The bug is in "file_manager.php" and according to a SecurityFocus advisory, is the result of failure to properly sanitize user input.

osCommerce is notorious for extremely long wait times between releases. The latest stable version is 2.2 RC2a and has been released more than two and a half years ago, on January 30, 2008. However, there are a few measures webmasters can take to protect their websites.

Third-party addons can be installed to prevent injection or cross-site scripting attacks, monitor all files for unauthorized changes or manage IP block lists. The permission for all files should never be set higher than 644 and the vulnerable "file_manager.php" file should be deleted.

"It has long been known the filemanger is a security risk & should, nay MUST be removed, if used for editing your site it is likely to damage your files, so is a bad utility to keep anyway [...]. Its also been known its a possible hacking route & to make matters worse there now exists a very nasty hack that uses filemanger to gain access to your site ( dbase included!! )," a forum post detailing osCommerce security tips, reads.

You can follow the editor on Twitter @lconstantin

TELL US WHAT YOU THINK:

4,385 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


OpenCart Riddled with Critical Security Holes

ASP and ASP.NET Websites Targeted in Mass SQL Injection Attack

Mass Injection Attack Targets Sites Hosted at BlueHost

Mass Injection Attack Hits WordPress Blogs across Multiple Hosters

Websites Hosted at Network Solutions Targeted in Mass Injection Attack

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM