General GM Chat When starting new posts, please specify YEAR, MAKE, MODEL, ENGINE type, and whatever modifications you have made. Chat about all things GM (and related cars). Off-topic stuff should be in the Lounge, and all Model specific mechanical problems should be posted in the proper forum.

WARNING: HOLD YOUR ONLINE ORDERS FOR ZZP!!!

Old 08-16-2007, 01:20 PM
  #1  
Senior Member
Posts like a Northstar
Thread Starter
 
rrounds's Avatar
 
Join Date: Feb 2003
Location: Sacramento, CA WCBF '06, '07 survivor
Posts: 658
Likes: 0
Received 0 Likes on 0 Posts
rrounds is on a distinguished road
Default WARNING: HOLD YOUR ONLINE ORDERS FOR ZZP!!!

just saw this on Club GP
http://www.clubgp.com/newforum/tm.as...mode=1&smode=1

could be trouble ?

ROD


(sticky by Admin, thanks for the info, Rod!)
Old 08-16-2007, 01:54 PM
  #2  
Senior Member
Certified Car Nut
 
bonnie94ssei's Avatar
 
Join Date: Oct 2002
Posts: 11,308
Likes: 0
Received 0 Likes on 0 Posts
bonnie94ssei is on a distinguished road
Default

I found this interesting in his first post:

I am NOT saying that there is any real risk that I have found.
then he says:

I believe there is a credible risk
Old 08-16-2007, 05:23 PM
  #3  
Senior Member
True Car Nut
 
LakevilleSSEi's Avatar
 
Join Date: Sep 2004
Location: Farmington, Minnesota =MWBF '05 SURVIVOR= =CEBF '06 SURVIVOR= =August '06 COTM=
Posts: 9,130
Likes: 0
Received 0 Likes on 0 Posts
LakevilleSSEi is on a distinguished road
Default

Typical BS......interesting though.....
Old 08-16-2007, 06:54 PM
  #4  
PopaDopaDo
True Car Nut
 
popatim's Avatar
 
Join Date: Jan 2005
Location: NY
Posts: 4,957
Likes: 0
Received 1 Like on 1 Post
popatim is on a distinguished road
Default

I got a ten spot says the culprit works for the hosting company.
Old 08-18-2007, 12:36 PM
  #5  
Senior Member
Posts like a Supercharger
 
13secGTP's Avatar
 
Join Date: May 2003
Location: Columbus, OH
Posts: 163
Likes: 0
Received 0 Likes on 0 Posts
13secGTP is on a distinguished road
Default

I got an email from that guy too. Whats funny is it came to my work email which is Whirlpool/Penske/GE specific. And no one knows it......

I have informed Zoom, and he told me to play along to see what else comes up.....
Old 08-21-2007, 10:11 AM
  #6  
Senior Member
True Car Nut
 
petraman's Avatar
 
Join Date: Jul 2006
Location: Granville, Ohio ~NEBF '07 Survivor~
Posts: 5,001
Likes: 0
Received 0 Likes on 0 Posts
petraman is on a distinguished road
Default

Are there any updates on this?
Old 08-21-2007, 06:55 PM
  #7  
Senior Member
Certified GM nut
 
McGrath's Avatar
 
Join Date: May 2005
Location: Wickliffe, Ohio
Posts: 2,155
Likes: 0
Received 0 Likes on 0 Posts
McGrath is on a distinguished road
Default

Yes could someone pm info as to whats going on here? I can't view the link and I have recently purchased things from ZZP.

Ed
Old 08-24-2007, 02:49 PM
  #8  
Senior Member
Posts like a Turbo
 
Speedster400's Avatar
 
Join Date: Dec 2006
Location: NHRA Division 3
Posts: 258
Likes: 0
Received 0 Likes on 0 Posts
Speedster400 is on a distinguished road
Default

So are there any updates? Is safeto order from ZZP again
Old 08-31-2007, 08:32 PM
  #9  
PopaDopaDo
True Car Nut
 
popatim's Avatar
 
Join Date: Jan 2005
Location: NY
Posts: 4,957
Likes: 0
Received 1 Like on 1 Post
popatim is on a distinguished road
Default

bump for an update if anyones heard anything...
Old 08-31-2007, 08:43 PM
  #10  
Senior Member
True Car Nut
 
petraman's Avatar
 
Join Date: Jul 2006
Location: Granville, Ohio ~NEBF '07 Survivor~
Posts: 5,001
Likes: 0
Received 0 Likes on 0 Posts
petraman is on a distinguished road
Default

Originally Posted by Zoomer via CGP
So far I have confirmations from people that do not have their email attached to clubGP who have recieved this spam.

I have also received confirmations from people who have never bought from ZZP or had their email attached to ZZP or the other sites who received the spam.

We're still working on the issue and haven't noticed anything strange log ins, changes to anything on the site, coupon codes added or changed, etc.

We have two separate comanies with teams pouring over our code. Neither has found any holes and the software. While based on OScommerce, our site is so highly modified from the orignal code, that the developer was offended when it was called OScommerce. Being this custom, it would be very difficult to hack into our site based on a hole in the code. We're still looking none-the-less. Even not finding anything, we are adding encription to coupon codes, customer data, and putting SSL? on the admin side. Should take effect shortly.

We have been in contact with helidirect and their software developer. They claim that their code is good. Their code and their site are totally different from ours. They also host with a completely different company. They did find the breach though and it relates to their server. For security reasons, I don't want to go into it further until they have completed the patches. We checked our site and server and we did not have the exploits affecting them.

No info from zipzoomfly, but I'm guessing that was added for email legitimacy.

On our site we are leaning towards a brute force attack stealing our admin password which would give them access to the site. He couldn't change code or get in super deep but he could get email addresses, change coupons, look up people'* order history and edit products. The only thing we ever noticed was that one coupon code and nothing more. Since changing our password, we haven't had issues. As a further step we will probably be changing hosts just in case. I'll post more info as I get it.
I believe it'* OK now

Thread Tools
Search this Thread
Quick Reply: WARNING: HOLD YOUR ONLINE ORDERS FOR ZZP!!!



All times are GMT -4. The time now is 08:43 AM.