Russian hacker selling how-to vid on exploiting unsupported Magento installations to skim credit card details for $5,000
- Reference: 1600176547
- News link: https://www.theregister.co.uk/2020/09/15/magento_1_exploit_sold_online/
- Source link:
Sansec, a software company focused on these so-called "digital skimming" attacks, discovered that 1,904 cyber-shops had been altered by miscreants over the weekend to include malicious JavaScript that siphoned off folks' card info.
"This automated campaign is by far the largest one that Sansec has identified since it started monitoring in 2015," it [1]said in a statement on Monday. "The previous record was 962 hacked stores in a single day in July last year."
The security biz estimated attackers have stolen personal data from "tens of thousands customers" so far. The intrusions can be traced back to a Magneto 1 zero-day exploit being sold by a Russian-speaking hacker going by the name "z3r0day" on a shady online forum.
For $5,000, z3r0day will show you a video on how to exploit a security hole in the web software to inject the digital-skimming code into an e-commerce site's files so that the code is run when a customer goes to a payment page on the hijacked site. No authentication is required. The hacker promised not to sell the exploit to more than 10 people to keep it under wraps and valuable.
Unfortunately, the vulnerability isn't easy to patch as the Adobe-owned Magento has ended support for the software. The best way to avoid such attacks is to migrate to Magento 2, a spokesperson from Sansec told El Reg . "Ideally they should upgrade to Magento 2, but we understand that merchants may need more time. Meanwhile, we recommend having server-side malware monitoring set up and to contract an alternative vendor for critical security patches."
Techies at Sansec have studied two servers with IP addresses in the US and France that were targeted by crooks armed with z3r0day's exploit. The payment details appear to have been funnelled through to a website hosted in Moscow. "We are not at liberty to disclose affected merchants. However, we have shared all relevant data with law enforcement today," the Sansec spokesperson told us. ®
Get our [2]Tech Resources
[1] https://sansec.io/research/largest-magento-hack-to-date
[2] https://whitepapers.theregister.com/
Rule #57 of deploying IT services:
If the cost/time/effort of doing an upgrade is greater than starting all over again, start all over again but this time with a product that supports upgrades better.
An upgrade should be just that - it shouldn't involve redevelopment of things. If going from v1 to v2 means everything you did on v1 is useless, then it's not v2. It's SomeOtherProduct v1.
Adobe you say? At least Microsoft cares for backwards compatibility and migration.
While I have no love of Adobe, this time it's not their fault. These are technical decisions that go back years before Adobe bought the company. Ebay had a much bigger influence in the development of Magento 2 and it shows because the two versions are radically different under the hood.
Anon because I'm such a dev who is dealing with this, and at the moment it pays the bills handsomely. Please don't judge me!
Still on sale?
Or have the 10 orders been filled?
Plastic fantastic
> For $5,000, z3r0day will show you a video on how to exploit a security hole in the web software to inject the digital-skimming code into an e-commerce site's files so that the code is run when a customer goes to a payment page on the hijacked site.
Will they take a credit card for payment?
" The best way to avoid such attacks is to migrate to Magento 2, a spokesperson from Sansec told El Reg. "
You don't migrate from Magento 1 to Magento 2. You completely redevelop your website to use Magento 2, as there is no reliable way to migrate the data across from version 1 to version 2. That's potentially hundreds of thousands of products, orders etc, that have to be brought across some how without affecting audits etc.
Adobe though could not give a damn about that little issue, meaning retailers are at the mercy of web development agencies to do it for them. The costs are going to be eye watering.
I do not envy any retailer or solitary dev dealing with this at the moment. I really don't.