News: 1600176547

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Russian hacker selling how-to vid on exploiting unsupported Magento installations to skim credit card details for $5,000

(2020/09/15)


Thousands of e-commerce stores built using Magento 1 have been poisoned with malicious code that steals customers' bank card information as they enter their details to order stuff online.

Sansec, a software company focused on these so-called "digital skimming" attacks, discovered that 1,904 cyber-shops had been altered by miscreants over the weekend to include malicious JavaScript that siphoned off folks' card info.

"This automated campaign is by far the largest one that Sansec has identified since it started monitoring in 2015," it [1]said in a statement on Monday. "The previous record was 962 hacked stores in a single day in July last year."

The security biz estimated attackers have stolen personal data from "tens of thousands customers" so far. The intrusions can be traced back to a Magneto 1 zero-day exploit being sold by a Russian-speaking hacker going by the name "z3r0day" on a shady online forum.

For $5,000, z3r0day will show you a video on how to exploit a security hole in the web software to inject the digital-skimming code into an e-commerce site's files so that the code is run when a customer goes to a payment page on the hijacked site. No authentication is required. The hacker promised not to sell the exploit to more than 10 people to keep it under wraps and valuable.

Unfortunately, the vulnerability isn't easy to patch as the Adobe-owned Magento has ended support for the software. The best way to avoid such attacks is to migrate to Magento 2, a spokesperson from Sansec told El Reg . "Ideally they should upgrade to Magento 2, but we understand that merchants may need more time. Meanwhile, we recommend having server-side malware monitoring set up and to contract an alternative vendor for critical security patches."

Techies at Sansec have studied two servers with IP addresses in the US and France that were targeted by crooks armed with z3r0day's exploit. The payment details appear to have been funnelled through to a website hosted in Moscow. "We are not at liberty to disclose affected merchants. However, we have shared all relevant data with law enforcement today," the Sansec spokesperson told us. ®

Get our [2]Tech Resources



[1] https://sansec.io/research/largest-magento-hack-to-date

[2] https://whitepapers.theregister.com/

wolfetone

" The best way to avoid such attacks is to migrate to Magento 2, a spokesperson from Sansec told El Reg. "

You don't migrate from Magento 1 to Magento 2. You completely redevelop your website to use Magento 2, as there is no reliable way to migrate the data across from version 1 to version 2. That's potentially hundreds of thousands of products, orders etc, that have to be brought across some how without affecting audits etc.

Adobe though could not give a damn about that little issue, meaning retailers are at the mercy of web development agencies to do it for them. The costs are going to be eye watering.

I do not envy any retailer or solitary dev dealing with this at the moment. I really don't.

Lee D

Rule #57 of deploying IT services:

If the cost/time/effort of doing an upgrade is greater than starting all over again, start all over again but this time with a product that supports upgrades better.

An upgrade should be just that - it shouldn't involve redevelopment of things. If going from v1 to v2 means everything you did on v1 is useless, then it's not v2. It's SomeOtherProduct v1.

Blackjack

Adobe you say? At least Microsoft cares for backwards compatibility and migration.

Anonymous Coward

While I have no love of Adobe, this time it's not their fault. These are technical decisions that go back years before Adobe bought the company. Ebay had a much bigger influence in the development of Magento 2 and it shows because the two versions are radically different under the hood.

Anon because I'm such a dev who is dealing with this, and at the moment it pays the bills handsomely. Please don't judge me!

Still on sale?

chivo243

Or have the 10 orders been filled?

Plastic fantastic

Pete 2

> For $5,000, z3r0day will show you a video on how to exploit a security hole in the web software to inject the digital-skimming code into an e-commerce site's files so that the code is run when a customer goes to a payment page on the hijacked site.

Will they take a credit card for payment?

If I kiss you, that is an psychological interaction.
On the other hand, if I hit you over the head with a brick,
that is also a psychological interaction.
The difference is that one is friendly and the other is not
so friendly.
The crucial point is if you can tell which is which.
-- Dolph Sharp, "I'm O.K., You're Not So Hot"