Magento says compromised sites haven't patched older vulnerabilities

Some Magento sites have been infected with the Neutrino exploit kit

Magento said Tuesday there does not appear to be a new vulnerability in its e-commerce platform that is causing some websites to become infected with the Neutrino exploit kit.

Some of the affected websites appear to not have patched a code execution vulnerability nicknamed the Shoplift Bug Patch, Magento's security team wrote in a blog post. A patch was released in February.

Other Magento-powered sites have not applied other patches, making them vulnerable.

The latest attack against Magento was highlighted by Malwarebytes and Sucuri, two security companies, who noticed attacks on the client and server sides.

The infected Magento sites contained malicious scripts that created iframes, which pulled content from the malicious domain "Guruincsite." That domain, which is blacklisted by Google, has been linked with the Neutrino exploit kit.

neutrino Malwarebytes

Malwarebytes showed how a person who lands on a compromised website running Magento is redirected to the Neutrino exploit kit

If encountered by someone browsing a website, exploit kits attack a computer, looking for software vulnerabilities in order to deliver malware. Hackers often try to plant code that triggers exposure to an exploit kit on legitimate, highly trafficked websites, as it creates an opportunity to infect many computers.

Malwarebytes saw client-side exploits coming from Neutrino that try to exploit Adobe Systems' Flash Player and installs malware called Andromeda/Gamarue, wrote Jerome Segura, a senior security researcher, on Sunday.

"Compromised machines can be harvested for financial credentials and also become part of a large botnet," he wrote.

Magento warned that even if all patches have been applied to the software, it's important to figure out if a website had been compromised prior to patching.

Even if a flaw has now been patched, it's possible the attackers created unauthorized administrative accounts, which would continue to give them access, Magento said.

Magento, which is owned by eBay, is an attractive target for attackers since it's used by a large number of companies, including Nike, Olympus and Ghirardelli Chocolate. It claims to be the most used software for the top 1 million websites ranked by Alexa.

 

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?