Twitter SMFHacks Facebook SMFHacks SMFHacks.com
** Home Forum Index Hacks Products Login Register Search
Welcome, Guest. Please login or register.
May 19, 2013, 10:14:27 pm

Login with username, password and session length
Members
Total Members: 10759
Latest: livingunique
Stats
Total Posts: 32356
Total Topics: 5476
Online Today: 72
Online Ever: 2482
(April 09, 2011, 07:02:45 pm)
Users Online
Users: 3
Guests: 41
Total: 44
+ 
|-+ 
| |-+ 
| | |-+ 
| | | |-+ 
| | | | |-+ 
0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: store being compromised?  (Read 1963 times)
Bar Nuthin
SMF Store Customer
Full Member
*****
Offline Offline

Posts: 101



View Profile WWW
« on: March 29, 2010, 03:46:13 pm »

i recently had a transaction where a user purchased multiple digital items - using paypal -  for $0.01

i confirmed that there were no coupons added or used. It looks like paypal returned a valid IPN

any idea how this user accomplished this?

the total for this order should have been around $50
Logged
lakestclair
Full Member
***
Offline Offline

Posts: 106



View Profile
« Reply #1 on: March 30, 2010, 07:56:23 am »

I just received this notification from Paypal...

Please check your server that handles PayPal Instant Payment Notifications (IPN). IPNs sent to the following URL(s) are failing:
 
http://www.lakestclairrun.com/storeipn.php
 
If you do not recognize this URL, you may be using a service provider that is using IPN on your behalf. Please contact your service provider with the above information. If this problem continues, IPNs may be disabled for your account.
 
Thank you for your prompt attention to this issue.
 
 
Thanks,
 
PayPal
Logged
SMFHacks
Administrator
Hero Member
*****
Offline Offline

Posts: 10989


View Profile
« Reply #2 on: March 30, 2010, 12:49:59 pm »

Bar Nuthin - I have seen that occur involves altering the url/item price of the transaction sent to paypal. I can give you some code to prevent low value purchases depending on what is the cheapest item you have with coupons.

lakestclair
That is safe to ignore. If you have it pointed to that file in your IPN profile on paypal that error may occur since that page does not exist.
The store automaticlly sets the correct path.
Logged
Bar Nuthin
SMF Store Customer
Full Member
*****
Offline Offline

Posts: 101



View Profile WWW
« Reply #3 on: March 31, 2010, 12:01:01 am »

i'd be interested in that code though it sounds like somebody could still purchase $100 worth of products and edit it to the lowest priced item in the store - if I understand you correctly


I'd be even more interested in how this is pulled off, if you could send me a PM

and are there any other methods to lock out this type of action?
Logged
lakestclair
Full Member
***
Offline Offline

Posts: 106



View Profile
« Reply #4 on: March 31, 2010, 12:15:07 am »



lakestclair
That is safe to ignore. If you have it pointed to that file in your IPN profile on paypal that error may occur since that page does not exist.
The store automaticlly sets the correct path.


This is the first time it's happened since I opened the store.  Happened again tonight..Same message.
Logged
Pages: [1] Go Up Print 
« previous next »
Jump to:  

Recent
[Today at 10:01:19 pm]

[Today at 08:18:27 pm]

[Today at 07:03:27 am]

[May 16, 2013, 10:13:46 pm]

[May 15, 2013, 11:32:14 pm]

[May 15, 2013, 11:31:24 pm]

[May 12, 2013, 09:10:43 am]

[May 10, 2013, 03:49:55 am]

[May 07, 2013, 07:12:40 pm]

[May 07, 2013, 02:37:14 pm]
Random Picture
Donate to SMFHacks.com
Help Support the SMFHacks.com mod making.
Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
TinyPortal v0.9.7 © Bloc
SMF and SimpleMachines are registered trademarks of Simple Machines. SMFHacks.com is not affiliated with nor endorsed by Simple Machines.
Page created in 1.287 seconds with 22 queries.