How safe is shopping on internet

Wednesday, April 27, 2005
In the latest days, they are possible to be read in different sites,
the news on the increase of the Phishing, today I want to raise a
reflection, whichever safe is to buy today in Internet in day?

Diabolic Crab has reported multitude of vulnerabilities in different
systems based on virtual stores, i myself I have reported some of
them,and others "vulns finders" and today considers to me cueston
to where have part of fault vendors or developers of software of
these increases of phishing?

Is trustworthy the content that this seeing or has been manipulated
before arriving at you? the developers of software day to day need a
new figure that is appraised in Internet "aplications to tester"
understood in looking for the new vulnerabilities in new products and
new programming languages...

A simple failure of validation can may to get to be reason for phishing
in its product? is a reality what the user in the purchases by Internet
are trusted when day to day they see themselves and continue seeing
that in if many of mayor products or CMS for e-comerce are not reliable even.

atentamente :
Lostmon (Lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Data Mangler of: http://www.osvdb.org
--
La curiosidad es lo que hace mover la mente.

PHPCart price manipulation

Tuesday, April 26, 2005
###############################################
PHPCart order price manipulation
vendor url: www.phpcart.net
advisory:http://lostmon.blogspot.com/2005/04/
phpcart-price-manipulation.html
vendor notify: yes exploit available: yes
OSVDB ID:15859
BID:13406
Secunia: SA15147
Securitytracker:1013892
################################################

PHPCart is a simple shopping system for small web-merchants
.Set-up of PHPCart is quick and easy, and does not require a database.

PHPcart contains a flaw that allows a price manipulation wen order a
product.This flaw exists because the application does not validate
'price' , 'postage' variables upon submission to the 'phpcart.php'
script. This could allow a user to create a specially crafted URL that
can shop some products at 0$, leading to a loss of integrity.


versions:

3.2 afected
3.3 not tested

also is posible all vesions prior to 3.2 are vulnerables.

##########
solution:
##########

upgrade to version 3.3 (not tested)
this version is not tested and is also posible to be vulnerable too.


##########
timeline
##########

discovered:25 april 2005
vendor notify 26 april 2005
vendor response:
vendor fix:
disclosure:27 april 2005


#####################
Proof of concept:
#####################


for exploiting this issue :

1 click in "add to cart" button on product what you are interested
the link have a similar looks :

http://[victim]/phpcart.php?action=add&id=1002&descr=Mobile%20
Phone&price=35.0&postage=10&quantity=1

if we look we have this variables ==>&price=35.0&postage=10 this is
the price of the product and the post cost.

in your cart you have now a product.

2. click on "view basket" and you have your product ... delete it and
click on this manipulate URL:

http://[victim]/phpcart.php?action=add&id=1002&descr=Mobile%20
Phone&price=0&postage=&quantity=100

we manipulate 'price' , 'postage' and 'quantity' and now if we look our
basket we have 100 products shopping at cost 0$


############### End ####################

thnx to estrella to be my ligth
thnx to all http://www.osvdb.org Team
thnx to all who day after day support me !!!
--
atentamente:
Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Data Mangler of: http://www.osvdb.org
--
La curiosidad es lo que hace mover la mente....

OneWorldStore user information disclosure

Sunday, April 24, 2005
##############################################
OneWorldStore user order information disclosure
vendor urL: http://www.oneworldstore.com/
advisory:http://lostmon.blogspot.com/2005/04/
oneworldstore-user-information.html
vendor confirmed: yes exploit available:yes
OSVDB ID:15781
Secunia: SA15104
Securitytracker:1013796
BID:13361
###############################################

vendor security url :
http://oneworldstore.com/support_security_issue_updates.asp
#April_24_2005_Lostmon


OneWorldStore contains a flaw that may lead to an unauthorized
information disclosure. The issue is triggered when a remote user
manipulates the value of variable 'idOrder' upon submit to
'PaymentMethods/owOfflineCC.asp' script occurs, which will
disclose name on credit card and the address from buyers this
information resulting in a loss of confidentiality.



versions :

OneWorldStore™ Free Store
OneWorldStore™ Basic Store
OneWorldStore™ SOHO Store
OneWorldStore™ Business Store
OneWorldStore™ Enterprise Store

#########
solution:
#########

vendor´s Patch :
http://oneworldstore.com/support_updates.asp

#########
timeline
#########

discovered on :24 april 2005
vendor notify 24 april 2005
vendor response 24 april 2005
vendor fix : 24 april 2005 ( 1 hour later WoW)
disclosure: 25 april 2005
##############
Proof of concept
##############


http://[victim]/owBasket/PaymentMethods/owOfflineCC.asp?idOrder=1
http://[victim]/owBasket/PaymentMethods/owOfflineCC.asp?idOrder=2
http://[victim]/owBasket/PaymentMethods/owOfflineCC.asp?idOrder=3
http://[victim]/owBasket/PaymentMethods/owOfflineCC.asp?idOrder=

thnx to estrella to be my ligth
thnx to all http://www.osvdb.org Team
thnx to all who day after day support me !!!
thnx to vendor very fast respose and very fast release a fix good work !!


--
atentamente:
Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Data Mangler of: http://www.osvdb.org
--
La curiosidad es lo que hace mover la mente....

OneWorldStore Critical Failure

Wednesday, April 20, 2005
################################################
OneWorldStore Critical Failure
vendor url:http://oneworldstore.com/
advisory:http://lostmon.blogspot.com/2005/04/
oneworldstore-critical-failure.html
vendor confirmed:yes exploit available: yes
OSVDB ID:15724
Secunia: SA15057
BID:13322
Securitytracker: 1013782
################################################

OneWorldStore contains a flaw that may allow a malicious user to
crash the application. The issue is triggered when a remote user
call directly '/owConnections/chksettings.asp' script occurs. It is
possible that the flaw may allow resulting in a loss of availability.

########
versions
#######

OneWorldStore basic
OneWorldStore free
OneWorldStore enterprise

########
solution:
########

OneWorldStore has release a wrokaround
http://www.oneworldstore.com/support_security_issue_updates.asp
#April_20_2005_Lostmon


workaround:

--delete (or rename) the /owConnections/chksettings.asp file.

timeline

discovered 19 april 2005
vendor notify 19 april 2005
vendor response:20 april 2005
vendor solution: 20 april 2005

proof of concept:

Failure method:

Run this file in a browser:
http://[domain name]/owConnections/chksettings.asp

Upon execution the site will shut down until a fix is applied. Each
site's fix is different. However, no data will be lost or exposed.

RESOULTION:
Delete the /owConnections/chksettings.asp prior to being hacked.

OneWorldStore Editions no longer use the /owConnections/chksettings.asp file.

this crashes the application, and a user can re-start only to step 2
without the fix..they need the fix to prevent it from happening
again

We would like to thank Lostmon for notifying us of these issues. Our
turnaround time for applying the fixes and releasing the patches was
approximately 5 hours. We have also asked him to post his advisory,
with our fix, on his website to help get the word out about the patch.
########### END ##############

thnx to estrella to be my ligth
thnx to all http://www.osvdb.org Team
thnx to all who day after day support me !!!
thnx to vendor very fast respose and very fast release a fix good work !!
thnx to icaro he is investigate with me :D
--
atentamente:
Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Data Mangle of: http://www.osvdb.org
--
La curiosidad es lo que hace mover la mente...
 

Browse

About:Me

My blog:http://lostmon.blogspot.com
Mail:Lostmon@gmail.com
Lostmon Google group
Lostmon@googlegroups.com

La curiosidad es lo que hace
mover la mente...

Friends