Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

Magento Online Stores- Hackers Are Stealing Credit Card Details Through Realex Payment Module

 

The Magento is a most used open source e-commerce platform, which had been released by Varien Inc. in March 2008. This PHP based e-commerce platform has millions of active user. The security firm Sucuri has detected a security incident, in which hackers are stealing payment card details of users from online Magento stores. To do so, hackers are abusing “Realex Payments” named Magento module, which is a payment gateway extension. All this has been revealed by Sucuri in its latest report on this Friday.

 

About Realex Payments

The European Payment Gateway “Realex Payments” is a division of Dublin-based “Global Payments Inc”. It was actually founded by an entrepreneur Colm Lyon in 2000 and had been acquired by Global Payments Inc. in 2015. It is a paid payment module and its price for Magento online stores is Euro 172 (US Dollars 193). The Realex Payments has around 14000 active clients including Vodafone Ireland, Paddy Power, and Virgin Atlantic Airways. This payment gateway is doing the transaction of more than 30 Billion Euros every year.

 

Where is the Vulnerability?

As I wrote above, the hackers are targeting “Realex Payments Magento Extension SF9.” This extension allows the Magento store owners to process telephone and email orders by entering payment card details. According to the security researchers, this Realex Payment module is not directly vulnerable. The hackers are abusing this module after hijacking the online Magento shop. The hackers are adding a malicious function “sendCcNumber()” to “Remote.php” named file. It is an SF9 file and this function is collecting financial and personal information of the users of targeted Magento store. The hackers are getting all the stolen information through an email. The details of this email address are available in “sendCcNumber()” function. An online service “binlist.net” is allowing users to identify the credit card issuer by entering first six digits of the card, the malicious function “sendCcNumber()” is leveraging this service as well.

 

How to Protect Online Magento Stores?

The security researchers at Sucuri has explained that a number of massive cyber-attacks had been detected by them in which attackers had injected hard coded malicious scripts into Magento stores. Most of the scripts had been written by the attackers to steal payment card data and in a number of cases, they successfully managed to steal it. The security researchers said we are talking about Magento stores only. The hackers are using various type of tactics to target other online platforms as well. The only way to protect the online stores from such types of attacks is regular security updates. Keep your Magento online store up to date. If a new update is available then install it as soon as possible. The hackers are expert in exploiting security loopholes and bypassing security techniques. Don’t give a single chance to hackers, they could put your business whole business at risk.

 

Also Read

Dark Web – 6,40,000 PlayStation User Accounts On Sale 

The Confidential Confide Messenger is Hackable, Claimed by Security Firm IOActive!

Android Latest Security Updates, More Than 100 Vulnerabilities Patched by Google

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.