Post by Colcreate » Wed Nov 20, 2024 7:17 am

Over the last few days one of my sites has received a dozens of new customer registrations with false details and with various IP addresses originating outside of the UK. There also seems to be a lot of 'Returns' entries being created and the error logs are filling up with various "Undefined index" for both return.php & contact.php
I am deleting the fake customers, blocking their IP address ranges, have temporarily disabled the return.php script and am logging activity on the site.

Can anybody advise on what might be going on here or had similar experiences?


Opencart Version 3.0.3.7
Default install

Newbie

Posts

Joined
Thu Oct 28, 2010 5:25 am

Post by by mona » Wed Nov 20, 2024 7:42 am

Yeah there are still lots of sites (not exclusive to Opencart) that do not implement security measures and bots / wannabe hackers exploit those.
Do you have any at all?

DISCLAIMER:
You should not modify core files .. if you would like to donate a cup of coffee I will write it in a modification for you.


https://www.youtube.com/watch?v=zXIxDoCRc84


User avatar
Expert Member

Posts

Joined
Mon Jun 10, 2019 9:31 am

Post by Colcreate » Wed Nov 20, 2024 8:04 am

Yes there are further elements of protection in place but it would still be beneficial to know if the same activity has been noted elsewhere and if it trying to exploit a vulnerability in Opencart 3.

Newbie

Posts

Joined
Thu Oct 28, 2010 5:25 am

Post by by mona » Wed Nov 20, 2024 8:19 am


DISCLAIMER:
You should not modify core files .. if you would like to donate a cup of coffee I will write it in a modification for you.


https://www.youtube.com/watch?v=zXIxDoCRc84


User avatar
Expert Member

Posts

Joined
Mon Jun 10, 2019 9:31 am

Post by khnaz35 » Thu Nov 21, 2024 12:42 am

You could use google recaptcha v3 to get rid of this problem.

Got an urgent question that’s keeping you up at night? There might just be a magical inbox ready to help: khnaz35@gmail.com
Enjoy nature ;) :) :-*


User avatar
Active Member

Posts

Joined
Mon Aug 27, 2018 11:30 pm
Location - Malaysia

Post by by mona » Thu Nov 21, 2024 1:04 am

Colcreate wrote:
Wed Nov 20, 2024 8:04 am
Yes there are further elements of protection in place but it would still be beneficial to know if the same activity has been noted elsewhere and if it trying to exploit a vulnerability in Opencart 3.
The OP confirmed they are using post protection and appears to be asking if there is a specific vulnerability that can be exploited.
If there were such a thing it would be a very stupid person who would write that vulnerability on a public forum.

DISCLAIMER:
You should not modify core files .. if you would like to donate a cup of coffee I will write it in a modification for you.


https://www.youtube.com/watch?v=zXIxDoCRc84


User avatar
Expert Member

Posts

Joined
Mon Jun 10, 2019 9:31 am

Post by paulfeakins » Thu Nov 21, 2024 7:31 pm

Colcreate wrote:
Wed Nov 20, 2024 7:17 am
Over the last few days one of my sites has received a dozens of new customer registrations with false details and with various IP addresses originating outside of the UK.
Our Advanced CAPTCHA should fix that: https://www.opencart.com/index.php?rout ... er=antropy

UK OpenCart Hosting | OpenCart Audits | OpenCart Support - please email info@antropy.co.uk


User avatar
Legendary Member

Posts

Joined
Mon Aug 22, 2011 11:01 pm
Location - London Gatwick, United Kingdom

Post by Johnathan » Thu Nov 21, 2024 9:43 pm

As far as I'm aware, there is no vulnerability to be exploited by bots creating fake registrations or fake returns. Nobody knows why someone created bots to do this --- I assume there's some benefit, but I can't think of one.

Image Image Image Image Image


User avatar
Administrator

Posts

Joined
Fri Dec 18, 2009 3:08 am


Post by Colcreate » Fri Nov 22, 2024 9:07 pm

Thank you all for your replies.
We improved our spam protection and blocked access to associated IP addresses & ranges identified in our logs. So far after 48hrs of monitoring the changes we haven't had any further false registrations. The only registrations now are genuine ones which we are happy to manually approve.
We originally asked about 'vulnerabilities' to try and understand why this was happening. We were seeing similar attacks coming in from dozens of different countries; from Albania to Zambia at different times of the day and with slightly different entry points, which suggests to us that there was more than one party responsible but all with a very specific focus.
The 'why' answer...? seems to be to simply generate an email response from the site and direct it to a 3rd party address. We have since received a handful of notifications for delayed, failed or returned emails and even the odd 'out of office' responses as a result.
There was nothing found (by us or our host) to suggest that once this email response is triggered that any more than the initial email is sent. Likewise there was nothing to indicate that the default content or headers of the email could be changed.

Oh well on to the next challenge.....

Newbie

Posts

Joined
Thu Oct 28, 2010 5:25 am
Who is online

Users browsing this forum: lockiedownunder and 11 guests