Slashdot Mirror


Critical Magento SQL Injection Flaw Could Soon Be Targeted By Hackers (csoonline.com)

itwbennett writes: The popular e-commerce platform Magento has released 37 security issues affecting both the commercial and open-source versions, four of which are critical. "Of those, one SQL injection flaw is of particular concern for researchers because it can be exploited without authentication," writes Lucian Constantine for CSO. Researchers from Web security firm Sucuri "have already reverse-engineered the patch [for that flaw] and created a working proof-of-concept exploit for internal testing," says Constantin. "The SQL vulnerability is very easy to exploit, and we encourage every Magento site owner to update to these recently patched versions to protect their ecommerce websites," the researchers warn in a blog post. "Unauthenticated attacks, like the one seen in this particular SQL Injection vulnerability, are very serious because they can be automated -- making it easy for hackers to mount successful, widespread attacks against vulnerable websites," the Sucuri researchers warned. "The number of active installs, the ease of exploitation, and the effects of a successful attack are what makes this vulnerability particularly dangerous." Since the researchers were able to create a working proof-of-concept exploit, it's only a matter of time until hackers discover a way to use the exploit to plant payment card skimmers on sites that have yet to install the new patch.

UPDATE: Onilab, an official Magento development partner, has a blog post explaining how you can update your store to the latest version of Magento.

14 comments

  1. Are the retard editors even trying? by Anonymous Coward · · Score: 0

    Same page
    https://m.slashdot.org/story/353912

    1. Re: Are the retard editors even trying? by Anonymous Coward · · Score: 1

      Apparently the SQL injection was used exploited to post a dupe on slashdot.

    2. Re: Are the retard editors even trying? by Anonymous Coward · · Score: 0

      Make apk an editor imo

    3. Re: Are the retard editors even trying? by Anonymous Coward · · Score: 0

      This is 2019. We don't say the "R" word anymore.

    4. Re: Are the retard editors even trying? by Anonymous Coward · · Score: 0

      Shut up faggot.

    5. Re: Are the retard editors even trying? by Anonymous Coward · · Score: 0

      But I am wetarded you insensitive clod!

    6. Re: Are the retard editors even trying? by Anonymous Coward · · Score: 0

      U mizspewd cwad, wetawd.

  2. Must be what Slashdot uses by Burdell · · Score: 2

    Explains the dupes - injection attacks!

    1. Re:Must be what Slashdot uses by Anonymous Coward · · Score: 0

      Explains the dupes - injection attacks!

      https://magewares.com/blog/protect-magento-site-sql-injection-flaw/

  3. Warming up for April Fools' by Powercntrl · · Score: 2

    Yep, the cat's out of the bag. On April 1st, it will be ALL DUPES, ALL DAY!

    --

    ---
    DRM is like antifreeze, to the MPAA/RIAA it's sweet, to the consumers it's poison.
  4. Pff... yeah right! by Gravis+Zero · · Score: 2

    Come on, they've been screaming about this vulnerability on Slashdot for literally hundreds of minutes. If they haven't exploited it by now then what are the chances they are going to all of the sudden change their minds and start exploiting it in the future? ;)

    --
    Anons need not reply. Questions end with a question mark.
    1. Re:Pff... yeah right! by Anonymous Coward · · Score: 0

      they've been screaming about this vulnerability on Slashdot for literally hundreds of minutes. If they haven't exploited it by now then what are the chances they are going to all of the sudden change their minds and start exploiting it in the future?

      Hmm, maybe you hadn't noticed but computer crimes are punished very harshly here in the United States. Remember Aaron Swartz? He was charged with two counts of wire fraud and eleven violations of the Computer Fraud and Abuse Act, carrying a cumulative maximum penalty of $1 million in fines, 35 years in prison, asset forfeiture, restitution, and supervised release. Imagine what they would dish out for actually deleting data or otherwise damaging a computer that was not yours. Does that answer your question?

  5. My Clone Army by MikeDataLink · · Score: 1

    has arrived... here on slashdot.

    --
    Mike @ The Geek Pub. Let's Make Stuff!
  6. But wait... by Anonymous Coward · · Score: 0

    I thought Magneto was supposed to be one of the bad guys, leading his antisocial mutants against Wheelchair-Captain-Picard and his pro-non-mutant, mutant-allies!