Posted - 12/08/2019 : 08:07:07
A client was recently hacked. After doing the usual file searches, upload new files, and so on. the problem was not fixed. Turns out the hack was in the database, cleverly hidden.
As you know, the input field for the Admin category name is about 30 spaces wide. The hacker put 45 spaces between the category name and the malicious script so you could not see it when viewing the category in the Admin. Even with downloading the categoryinventory page, it was not readily visible as Excel defaults to column widths of about an inch and, with text in the 'sectionWorkingName' column, the additional text in the 'sectionName' column is hidden.
If you suspect a hack or are getting security warnings (mentioning google-smart) when you open a page, download your category inventory and product inventory files and search for <script> before you drive yourself crazy going through every page and ECT file.
As a side note, the hack is from China and the actual malicious script is on another server. The script in the hack is a document.write script.
And I say "New Malicious Hack" as I have not seen this spacing trick before.
Marshall CENLYT Productions - ms designs Affordable Web Design Custom Ecommerce Designs Responsive Websites Cenlyt.com
|