Index Of /orders.log
Inurl: Shopadmin.asp
Hack Shopadmin
Recently Hacked
![Hack Hack](https://i.ytimg.com/vi/niByuzr_mBs/hqdefault.jpg)
Printed from: VP-Cart StoreFront Customer Forum
Topic URL:https://www.vpcart.com/virtprog/vpaspforum/topic.asp?TOPIC_ID=689
Printed on: September 08 2020 Kawasaki zxr 750 j manual.
Topic:
Topic author: toocharming
Subject: Recently Hacked
Posted on: August 14 2002 22:59:13
Message:
Our VPASP database was hacked into recently. The hacker successfully discovered the correct username/password combination to log into the Administration page.
I wrote some asp scripts to email us whenever someone attempts to access shopadmin.asp or shopadmin1.asp. I am also writing some additional code to lock out unsuccessful login after 3 attempts. Gilles peterson brazilika zip. I am further considering a SSL certificate.
Anyone else experience hacking recently?
Tom
Replies:
![Shopadmin Shopadmin](https://4.bp.blogspot.com/-ZjHtrbDN0Jw/Un79W0sAL_I/AAAAAAAAKYU/zxZDDSGjZIc/s1600/Chord+Gitar+Letto+-+Ruang+Rindu.jpg)
Reply author: kwjoey
Replied on: January 30 2003 06:45:17
Message: Synthesia full version free.
I just got hacked. The hacker changed my admin password in the database. I don't understand how this happened.
My database is located in the directory- C:DATA
It is not browsable. Is it possible to hack into the directory from the domain name? Like typing http://domain.com/c:/data .cause I don't think so.
I'm using VPASP 3.50.
I had removed all files used for conversion and installation, as well as all files starting with C, the Session list utility, Database test utility, and the Template testing utility.
Of course my password was changed from the default one.
Here's what wasn't done before I was hacked.
I didn't change the name of my login page so the hacker could get to that. And I didn't use the login page with the 2nd password that hard-coded in shopadmin.asp. I have since done this.
I figure the hacker must have used a brute force attack to crack the password because the db file was not downloadable.
Does anybody have any other ideas for me?
Reply author: Superal
Replied on: January 30 2003 15:57:05
Message:
I take it that you have your own server. There are many security issues that pertain to servers alone. Without these measures in place, VPASP is vulnerable. Remember these guys have tools to open the cracks in the server holes. Close em.
Look at the lastest virus attacks on servers only. The security issue has been known for over 6 months but unless you are persistant on updating you see what happens.