[14518] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Back Door in Commercial Shopping Cart

daemon@ATHENA.MIT.EDU (Anik)
Fri Apr 14 12:10:07 2000

Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Message-Id:  <20000413181354.A27218@cpu1815.adsl.bellglobal.com>
Date:         Thu, 13 Apr 2000 18:13:54 -0400
Reply-To: Anik <anik@IFDO.PUGMARKS.COM>
From: Anik <anik@IFDO.PUGMARKS.COM>
X-To:         BUGTRAQ@SECURITYFOCUS.COM
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <Pine.LNX.3.95.1000411171050.24527G-100000@animal.blarg.net>

t's been a while since I have looked at the dansie shopping script (almost a
year now). As I remember it, the program also required you (or at least
strongly encouraged) making the script world writeable. As I no longer have
access to the script, I can't double check.
This reinforces the copy protection theory, but also allows a potential
attacker to do other interesting things to the script with much ease.
Anik



On Tue, Apr 11, 2000 at 05:24:06PM -0700, Joe wrote:
> Trojanized Commercial Shopping Cart
> ===============================================================
>
> Dansie Shopping Cart
>
> Version  : 3.04 (presumably earlier versions as well)
> Author   : Craig Dansie
> URL      : http://www.dansie.net/
> Language : Perl (both NT and Unix platforms are vulnerable)
> License  : Commercial, starting at $150.00
>            Copyright Dec 10, 1997-2000, Dansie Website Design
>
>
> Synopsis : This program -deliberately- allows arbitrary commands to be
>            executed on the victim server.
>
[snip]
>
> --
> Joe                                     Technical Support
> General Support:  support@blarg.net     Blarg! Online Services, Inc.
> Voice:  425/401-9821 or 888/66-BLARG    http://www.blarg.net

home help back first fref pref prev next nref lref last post