Skip to main content

File Insertion

More
9 years 9 months ago #256871 by saejangracer
File Insertion was created by saejangracer
-- HikaShop version -- : 2.6.4

Hi Hikashop,

Have recently discovered 2 Hikashop files modified on my site but not by me:

1. /administrator/components/com_hikashop/extensions/mail.php
I checked the last backup and this file didn't exist in this location. The content of the file is a PHP code to upload, move and rename a file.

2. /administrator/components/com_hikashop/extensions/plg_hikashop_massaction_category/indexa.html
I deleted this file because it contains a URL to a malware source file.

What should I do with the mail.php file? Is it a legitimate hikashop file in the right place, or was it maliciously inserted?

Also does this mean there's an open vulnerability in Hikashop 2.6.4 for the insertion to happen?

Thank you =)

Please Log in or Create an account to join the conversation.

More
9 years 9 months ago #256886 by nicolas
Replied by nicolas on topic File Insertion
Hi,

Both of these files don't exist by default in HikaShop.
So they were indeed maliciously inserted.
Does that mean that there is an open vulnerability on your website ? It's highly likely yes. Maybe you updated your extensions/Joomla in the mean time and that vulnerability has been closed already. The best would be to contact a security specialist like aesecure in order to check on it.
Does that mean that there is an open vulnerability on HikaShop 2.6.4 ? Not at all. It could be, but in that case, it would likely have already been reported and fixed, and many other websites would have been infected, especially ours.
So far, we had only one security issue reported and fixed in 7 years (and it was a few years ago). We try really hard to code in a secure way.

Please Log in or Create an account to join the conversation.

More
9 years 9 months ago #257001 by saejangracer
Replied by saejangracer on topic File Insertion
Hi nicolas,

Noted your advice, I will get hosting provider to assist on the matter since it's not a Hikashop vulnerability

Thank you =)

Please Log in or Create an account to join the conversation.

Time to create page: 0.220 seconds
Powered by Kunena Forum