SMFHacks.com
** Home Forum Index Hacks Products Login Register Search
Welcome, Guest. Please login or register.
May 24, 2012, 06:03:18 pm

Login with username, password and session length
Members
Total Members: 10071
Latest: cdavidson012
Stats
Total Posts: 28687
Total Topics: 4977
Online Today: 94
Online Ever: 2482
(April 09, 2011, 07:02:45 pm)
Users Online
Users: 2
Guests: 47
Total: 49
+ 
|-+ 
| |-+ 
| | |-+ 
| | | |-+ 
| | | | |-+ 
0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: store being compromised?  (Read 1394 times)
Bar Nuthin
SMF Store Customer
Jr. Member
*****
Offline Offline

Posts: 98



View Profile WWW
« on: March 29, 2010, 03:46:13 pm »

i recently had a transaction where a user purchased multiple digital items - using paypal -  for $0.01

i confirmed that there were no coupons added or used. It looks like paypal returned a valid IPN

any idea how this user accomplished this?

the total for this order should have been around $50
Logged

see my smf stores at www.psthemes.com and www.tiltbuster.com
lakestclair
SMF Gallery Pro Customer
Full Member
*****
Offline Offline

Posts: 103


View Profile
« Reply #1 on: March 30, 2010, 07:56:23 am »

I just received this notification from Paypal...

Please check your server that handles PayPal Instant Payment Notifications (IPN). IPNs sent to the following URL(s) are failing:
 
http://www.lakestclairrun.com/storeipn.php
 
If you do not recognize this URL, you may be using a service provider that is using IPN on your behalf. Please contact your service provider with the above information. If this problem continues, IPNs may be disabled for your account.
 
Thank you for your prompt attention to this issue.
 
 
Thanks,
 
PayPal
Logged
SMFHacks
Administrator
Hero Member
*****
Offline Offline

Posts: 9678


View Profile
« Reply #2 on: March 30, 2010, 12:49:59 pm »

Bar Nuthin - I have seen that occur involves altering the url/item price of the transaction sent to paypal. I can give you some code to prevent low value purchases depending on what is the cheapest item you have with coupons.

lakestclair
That is safe to ignore. If you have it pointed to that file in your IPN profile on paypal that error may occur since that page does not exist.
The store automaticlly sets the correct path.
Logged
Bar Nuthin
SMF Store Customer
Jr. Member
*****
Offline Offline

Posts: 98



View Profile WWW
« Reply #3 on: March 31, 2010, 12:01:01 am »

i'd be interested in that code though it sounds like somebody could still purchase $100 worth of products and edit it to the lowest priced item in the store - if I understand you correctly


I'd be even more interested in how this is pulled off, if you could send me a PM

and are there any other methods to lock out this type of action?
Logged

see my smf stores at www.psthemes.com and www.tiltbuster.com
lakestclair
SMF Gallery Pro Customer
Full Member
*****
Offline Offline

Posts: 103


View Profile
« Reply #4 on: March 31, 2010, 12:15:07 am »



lakestclair
That is safe to ignore. If you have it pointed to that file in your IPN profile on paypal that error may occur since that page does not exist.
The store automaticlly sets the correct path.


This is the first time it's happened since I opened the store.  Happened again tonight..Same message.
Logged
Pages: [1] Go Up Print 
« previous next »
Jump to:  

Recent
[Today at 08:02:50 am]

[Today at 04:11:41 am]

[May 21, 2012, 08:54:11 am]

[May 20, 2012, 11:06:52 am]

[May 20, 2012, 05:58:11 am]

[May 19, 2012, 06:16:58 pm]

[May 19, 2012, 05:42:37 pm]

[May 18, 2012, 03:08:38 pm]

[May 17, 2012, 06:07:46 pm]

[May 17, 2012, 02:22:07 pm]
Random Picture
Donate to SMFHacks.com
Help Support the SMFHacks.com mod making.
Powered by SMF 1.1.16 | SMF © 2006-2011, Simple Machines LLC
TinyPortal v0.9.7 © Bloc
SMF and SimpleMachines are registered trademarks of Simple Machines. SMFHacks.com is not affiliated with nor endorsed by Simple Machines.
Page created in 0.221 seconds with 22 queries.