Loaded Commerce Community

Banner


Board index » Loaded Commerce Support » Security Issues

All times are UTC - 5 hours




Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: Site Hacked
PostPosted: Sun Mar 28, 2010 5:34 pm 
Offline
CRE Newbie

Joined: Wed Jul 15, 2009 5:09 pm
Posts: 2
hello

I have been reading about the security issues and applied the creloaded62pro_v6.2.14a_Security_PHPSELF patch last week or so and today the site was hacked
and index.php was changed.I am still looking at what else may have been messed with.

Is there something new to look for ?
I am not a pro with cre and would appreciate some help on what to do to secure the site
and what steps to take now

Thank you in advance


Top
 Profile  
 
 Post subject: Re: Site Hacked
PostPosted: Thu Apr 08, 2010 8:21 am 
Offline
CRE Legend

Joined: Sun Nov 09, 2003 1:00 am
Posts: 7301
Location: Baconton, GA USA
There are loads of things that can be done to secure a site, and many which should be, the question is generally where to start.

The source of around 80 to 90% of all security issues can be found by visiting your nearest mirror, or calling your hosting service provider. That makes this a good place to start.

Is your FTP password the same as your cPanel password? Stop that!

Is your FTP password under 8 characters, all lowercase or all upper case, lacking a numerical character or a special character such as an underscore? Fix that.

Is your FTP password more than 30 to 60 days old? Fix that.

Are you using insecure (aka "standard" or "normal") FTP?? Stop that.

Do you have SSL configured and in use on your site? If not, fix that.

Does your host use the default SSL certificate provided by the control panel vendor to secure your control panel? Fix that, even if it means moving the site.

Seems you've already avoided another big mistake, relying only upon foreign payment handling for "PCI Compliance" as your sole effort towards operating a secure website. PCI standards are very helpful in identifying and meeting most security needs. But they are only useful when applied at every step of operations. To do otherwise is like buying condoms with holes in them. Such systems should only be used as a component of a complete security plan.

You've also taken one of the most important steps towards addressing the remaining 10 to 20 % of issues - posting the problem here makes the developers aware that issues may exist.

Another action you can take in that regard is the regular use of a scanning service. There are a number of services which will provide the minimal scanning required for PCI compliance on a quarterly basis free of charge.

Use one of these services.

If you need help with that, there are site operations management services available, and you might want to consider one.

_________________
My CRE Loaded FAQ List
CRE Loaded Hosting


Top
 Profile  
 
 Post subject: Re: Site Hacked
PostPosted: Thu May 20, 2010 4:38 pm 
Offline
CRE Newbie

Joined: Wed Jul 15, 2009 5:09 pm
Posts: 2
ThankYou
Nimitz1061 for your advice


Top
 Profile  
 
 Post subject: Re: Site Hacked
PostPosted: Sat May 22, 2010 9:59 am 
Offline
CRE Freak

Joined: Thu Feb 22, 2007 1:00 am
Posts: 69
For protecting admin area you can also follow guide lines in http://blog.wasimasif.com/hardening-pro ... dmin-area/

_________________
http://www.infolates.com/


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

Board index » Loaded Commerce Support » Security Issues

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
It is currently Thu May 24, 2012 9:01 am
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group

Login

Forums Latest Activity

Top Listing

1. Cart2Cart - Shopping...
    Category: Shopping Cart Database Conversion Scripts
    
2. Points & Rewards PLUS!...
    Category: Add-Ons
    
3. Configuration Server...
    Category: Fixes
    
4. Credit Card with CCV
    Category: Payment Modules
    
5. CC7333_ATS
    Category: Templates
    
Show more...

© CRE Loaded is a product of Chain Reaction Ecommerce, Inc. Usage & Privacy Policy