Knowband Module One Page Checkout, Social Login & Mailchimp 1.7.x 9.0.2

No permission to download
thanks to dear member @richard updated Knowband Module One Page Checkout, Social Login & Mailchimp 1.7.x with a new update entry:

08-Jan-2024


Read the rest of this update entry...
 

Hello Guys, Be careful with this module, it has a security flaw with a back door....Here I share the information that another colleague "Coolt" passed on elsewhere:

Be crefull there is a hacker ho try to hack the "super checkout module" through vulnerabilities with php:

1- Try to check your logs, you must retrieve a user agent called "python"
2- Check your module files through ftp

- Files/path witch he try to access:

?fc=module&module=supercheckout&controller=supercheckout&ajax=1&method=SaveFilesCustomField

and

/modules/supercheckout/views/img/upload/1709889405_2024x2024x_xsamxadoo.php.php


=> Examine any file that you are unsure of, and look for code changes to existing files, especially php files.
 
Last edited: