News:

AbanteCart v1.4.2 is released.

Main Menu

Do you like AbanteCart? Please rate AbanteCart or share your experience with other eCommerce entrepreneurs. Go to Softaculous rating page to add your rating or write a review

Hacking attempt?

Started by everchanging, April 21, 2018, 01:51:02 PM

Previous topic - Next topic

everchanging

Hi Guys I have a question:

While looking at reports > customers > online and looking at the Url Accessed I see the following:


....&currency=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd%00



Is it me or is this a hacking attempt?
If so, is there reason for concern?
"I know one thing; that I know nothing"

abantecart

There are many robot computers that run hack attempts based on know vulnerabilities in known applications.
They first try to detect type of application and apply some hack. If it succeeds, they penetrate the system.

Based on what you posted, it is not a problem, but can you share entire request?
Please  rate your experience or leave your review
We need your help to build better free open source ecommerce platform for everyone. See how you can help

everchanging

#2
Hi

the request looks like this:


[b].......(folder of abantecart)...[/b]/index.php?rt=product/product&product_id=142&currency=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd%00



while the previous attempt looked like this:


index.php?rt=product/product&product_id=142&currency=../../../../../../../etc/passwd
"I know one thing; that I know nothing"

abantecart

These are attempts to grab your password file from the system. It will not happen.
Please  rate your experience or leave your review
We need your help to build better free open source ecommerce platform for everyone. See how you can help

everchanging

OK... good to know  :)

Thank you for your replies and clarifications  :)
"I know one thing; that I know nothing"

Forum Rules Code of conduct
AbanteCart.com 2010 -