Jump to content

security warning possible bug attack


slic535

Recommended Posts

[11-Jan-2015 17:36:06 UTC] PHP Warning:  Invalid Security Token in /home3/slic535/public_html/classes/sanitize.class.php on line 120
[11-Jan-2015 19:33:17 UTC] PHP Warning:  Stored session data did not match DB record. Session aborted as possible session hijack. Old IP Address: '24.145.131.82' New IP Address: '24.145.131.82' Old User Agent: 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10) AppleWebKit/600.1.25 (KHTML, like Gecko) Version/8.0 Safari/600.1.25' New User Agent: 'Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53' in /home3/slic535/public_html/classes/session.class.php on line 640
[11-Jan-2015 20:28:59 UTC] PHP Warning:  Security Warning: Illegal array key "amp;catId" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[11-Jan-2015 16:29:44 America/Chicago] PHP Warning:  array_merge() [<a href='http://docs.php.net/manual/en/function.array-merge.php'>function.array-merge.php</a>]: Argument #1 is not an array in /home3/slic535/public_html/classes/cubecart.class.php on line 833
[11-Jan-2015 22:43:22 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[11-Jan-2015 22:55:11 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[11-Jan-2015 23:33:50 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 00:22:23 UTC] PHP Warning:  Stored session data did not match DB record. Session aborted as possible session hijack. Old IP Address: '50.143.182.243' New IP Address: '50.143.182.243' Old User Agent: 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.1.25 (KHTML, like Gecko) Version/8.0 Safari/600.1.25' New User Agent: 'Mozilla/5.0 (iPhone; CPU iPhone OS 7_0 like Mac OS X) AppleWebKit/537.51.1 (KHTML, like Gecko) Version/7.0 Mobile/11A465 Safari/9537.53' in /home3/slic535/public_html/classes/session.class.php on line 640
[12-Jan-2015 01:10:03 UTC] PHP Warning:  Security Warning: Illegal array key "sort%255Bprice%255D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 02:23:24 UTC] PHP Warning:  Stored session data did not match DB record. Session aborted as possible session hijack. Old IP Address: '67.86.3.131' New IP Address: '67.86.3.131' Old User Agent: 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5' New User Agent: 'Mozilla/5.0 (iPhone; CPU iPhone OS 8_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12B410 Safari/600.1.4' in /home3/slic535/public_html/classes/session.class.php on line 640
[12-Jan-2015 07:21:57 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 08:41:56 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 10:28:27 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 12:51:39 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 08:06:37 America/Chicago] PHP Warning:  Shipping not setup or allow no shipping not enabled in /home3/slic535/public_html/classes/cubecart.class.php on line 1489
[12-Jan-2015 08:06:37 America/Chicago] PHP Warning:  Shipping not setup or allow no shipping not enabled in /home3/slic535/public_html/classes/cubecart.class.php on line 1489
[12-Jan-2015 14:39:50 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 14:49:15 UTC] PHP Warning:  Stored session data did not match DB record. Session aborted as possible session hijack. Old IP Address: '24.24.207.6' New IP Address: '24.24.207.6' Old User Agent: 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/600.2.5 (KHTML, like Gecko) Version/8.0.2 Safari/600.2.5' New User Agent: 'Mozilla/5.0 (iPhone; CPU iPhone OS 8_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12B410 Safari/600.1.4' in /home3/slic535/public_html/classes/session.class.php on line 640
[12-Jan-2015 15:48:02 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 16:50:56 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 20:42:21 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 21:13:41 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 22:21:33 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 22:55:39 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 23:35:29 UTC] PHP Warning:  Security Warning: Illegal array key "_a%3" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 18:02:41 America/Chicago] PHP Warning:  Cannot unset offset in a non-array variable in /home3/slic535/public_html/classes/cart.class.php on line 1058
[13-Jan-2015 00:08:06 UTC] PHP Warning:  Invalid Security Token in /home3/slic535/public_html/classes/sanitize.class.php on line 120
[13-Jan-2015 01:36:18 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[13-Jan-2015 02:38:39 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bprice%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85
[12-Jan-2015 21:07:30 America/Chicago] PHP Warning:  Invalid argument supplied for foreach() in /home3/slic535/public_html/classes/order.class.php on line 1108
[13-Jan-2015 03:21:28 UTC] PHP Warning:  Stored session data did not match DB record. Session aborted as possible session hijack. Old IP Address: '24.247.4.124' New IP Address: '24.247.4.124' Old User Agent: 'Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.0.4) Gecko/20100101 Firefox/4.0' New User Agent: 'Mozilla/5.0 (Linux; Android 4.4.2; RCT6773W22 Build/KOT49H) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/30.0.0.0 Safari/537.36' in /home3/slic535/public_html/classes/session.class.php on line 640
[13-Jan-2015 03:25:07 UTC] PHP Warning:  Security Warning: Illegal array key "sort%5Bname%5D" was detected and was removed. in /home3/slic535/public_html/classes/sanitize.class.php on line 85

 I found this in my error logs. I have had some people not being able to order because it 0.00 zeros out everything. could this be the culprit? how do I fix this? or is this a bug? I updated to the newest update 5.2.16

Link to comment
Share on other sites

Ignore all the Stored session data did not match DB record errors. This was probably someone checking out what your store's Mobile skin looks like. (You did ask about this, if I recall.) To do so, they needed to have their browser send a user-agent string that CubeCart recognizes as a mobile device. Sending the same cookie (and thus the same session) with a different user-agent or IP address is a security violation. When the violation occurs, CubeCart dumps the session - and that means logged in status, cart contents, issuing a fresh cookie, etc.

 

Apparently, you have no shipping modules enabled.

 

The Illegal array keys are interesting. We will need to find out what it is about the skin or URL generator that is causing a problem with the View Category sorters.

 

The others should be looked at. But, actually, there are several instances of coding (not really mistakes, per se) irregularities that are inconsequential. We would need to verify each of the rest of the error lines.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...