CRE Loaded Community

Banner


Board index » Loaded Commerce Support » Security Issues

All times are UTC - 5 hours




Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: Code entering php files
PostPosted: Sat May 02, 2009 11:52 am 
Offline
CRE Addict
User avatar

Joined: Sun Jan 09, 2005 1:00 am
Posts: 196
Location: English Lake District
My car started to come up with errors and stopped clients going through to checkout, on investigation i have discovered a huge amount of code has appeared in the login.php file a small sample of which is below, how can I stop this vunerability.
I am on CRE Loaded6 v6.2 Standard White Label with patch:07

<?php @register_shutdown_function("__sfd1235750811__");function __sfd1235750811__() { global $__sdv1235750811__; if (!empty($__sdv1235750811__)) return; $__sdv1235750811__=1; echo <<<DOC__DOC<!-- [b5167ea1bb68ce831eb34054de53ba73 --><font style='position: absolute;overflow: hidden;height: 0;width: 0'><ul><li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=2817">buy QuarkXPress 8</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1867">buy cheap QuarkXPress 8</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1436">buy software 8 QuarkXPress cheap</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=943">buy cheapest QuarkXPress 8</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=2702">buy QuarkXPress 8 full version</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1369">buy and download QuarkXPress 8 software</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1949">QuarkXPress 8 program purchase</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=3085">buy 8 online QuarkXPress</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1370">purchase order QuarkXPress 8 software</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=378">8 buy used QuarkXPress</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=53">buy QuarkXPress 8 inexpensive</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=27">buy QuarkXPress 8 price</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1514">download QuarkXPress cheap 8</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=2137">where to buy cheap Readiris Pro 11</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=187">where can i buy Readiris Pro 11</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=523">buy Readiris Pro 11</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1400">buy cheap Readiris Pro 11</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1464">buy cheap Readiris Pro 11 software</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=3437">buy cheapest Readiris Pro 11</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=308">buy Readiris Pro 11 full version</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=721">buy and download Readiris Pro 11 software</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=69">Pro 11 purchase Readiris program</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1089">buy Readiris Pro 11 online</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=671">purchase order Readiris Pro 11 software</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=2190">buy used Readiris Pro 11</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=3332">buy Readiris Pro 11 inexpensive</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=135">buy Readiris Pro 11 price</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=3135">Readiris Pro 11 cheap download</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=860">where to buy cheap Roxio Copy & Convert 3</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=149">where can i buy Roxio Copy & Convert 3</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=142">buy Roxio Copy & Convert 3</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=177">buy cheap Roxio Copy & Convert 3</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1990">buy cheap Roxio Copy & Convert 3 software</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1545">buy cheapest Roxio Copy & Convert 3</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1101">buy Roxio Copy & Convert 3 full version</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=1270">buy and download Roxio Copy & Convert 3 software</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=2837">Roxio Copy & Convert 3 program purchase</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=2973">buy Roxio Copy & Convert 3 online</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=908">purchase order Roxio Copy & Convert 3 software</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=771">buy used Roxio Copy & Convert 3</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=3333">buy Roxio Copy & Convert 3 inexpensive</a></li> <li><a href="http://www.prime-task.com/images/pti0.php?mysql0=1&page=942">buy Roxio Copy & Convert 3 price</a></li> <li><a href="http://www.prime-task.com/


Top
 Profile  
 
 Post subject: Re: Code entering php files
PostPosted: Sat May 02, 2009 2:56 pm 
Offline
CRE Legend
User avatar

Joined: Fri Jan 13, 2006 1:00 am
Posts: 11074
Location: Nappanee Indiana
if you followed the security issues in 6.2

you need to have patched to no less than patch 12

But that isn't to say you were hacked from your script, but from somewhere else on the shared server you are on.. contact your host

and PATCH asap

_________________
Jason Miller
https://www.creloadedexpert.com
CRE Loaded Expert Team
CRE Loaded Support
Home of the FIRST 100% tableless CRE Loaded template


Top
 Profile  
 
 Post subject: Re: Code entering php files
PostPosted: Sat May 02, 2009 7:28 pm 
Offline
CRE Addict
User avatar

Joined: Sun Jan 09, 2005 1:00 am
Posts: 196
Location: English Lake District
Many thanks for your reply.
I have gone round in circles looking for the patches you recommend and can't find them anywhere, could you be kind enough to put a link to them here for me.

Thanks in advance


Top
 Profile  
 
 Post subject: Re: Code entering php files
PostPosted: Sat May 02, 2009 7:44 pm 
Offline
CRE Legend
User avatar

Joined: Fri Jan 13, 2006 1:00 am
Posts: 11074
Location: Nappanee Indiana
you download them from where you obtained the software

if it was here.. top left creloaded icon.. log in, and on the my account page, you will see downloads

_________________
Jason Miller
https://www.creloadedexpert.com
CRE Loaded Expert Team
CRE Loaded Support
Home of the FIRST 100% tableless CRE Loaded template


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

Board index » Loaded Commerce Support » Security Issues

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
It is currently Wed Feb 08, 2012 7:36 am
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group

Login

Top Listing

1. Cart2Cart - Shopping...
    Category: Shopping Cart Database Conversion Scripts
    
2. Points & Rewards PLUS!...
    Category: Add-Ons
    
3. Configuration Server...
    Category: Fixes
    
4. Credit Card with CCV
    Category: Payment Modules
    
5. CC7333_ATS
    Category: Templates
    
Show more...

Follow Us on Twitter

An error occurred

Oops, an error seems to have occurred. We're sorry for any inconvenience this might have caused. If the error persists, feel free to tell us about it.

CRE Loaded Community Chat hosted by CRE Loaded.

Join now


Chat about what's on your mind. More about public chats.


© CRE Loaded is a product of Chain Reaction Ecommerce, Inc. Usage & Privacy Policy