General GM Chat When starting new posts, please specify YEAR, MAKE, MODEL, ENGINE type, and whatever modifications you have made. Chat about all things GM (and related cars). Off-topic stuff should be in the Lounge, and all Model specific mechanical problems should be posted in the proper forum.

WARNING: HOLD YOUR ONLINE ORDERS FOR ZZP!!!

Thread Tools
 
Search this Thread
 
Old Aug 16, 2007 | 01:20 PM
  #1  
rrounds's Avatar
Thread Starter
Senior Member
Posts like a Northstar
 
Joined: Feb 2003
Posts: 658
Likes: 0
From: Sacramento, CA WCBF '06, '07 survivor
rrounds is on a distinguished road
Default WARNING: HOLD YOUR ONLINE ORDERS FOR ZZP!!!

just saw this on Club GP
http://www.clubgp.com/newforum/tm.as...mode=1&smode=1

could be trouble ?

ROD


(sticky by Admin, thanks for the info, Rod!)
Reply
Old Aug 16, 2007 | 01:54 PM
  #2  
bonnie94ssei's Avatar
Senior Member
Certified Car Nut
 
Joined: Oct 2002
Posts: 11,308
Likes: 2
bonnie94ssei is on a distinguished road
Default

I found this interesting in his first post:

I am NOT saying that there is any real risk that I have found.
then he says:

I believe there is a credible risk
Reply
Old Aug 16, 2007 | 05:23 PM
  #3  
LakevilleSSEi's Avatar
Senior Member
True Car Nut
 
Joined: Sep 2004
Posts: 9,130
Likes: 0
From: Farmington, Minnesota =MWBF '05 SURVIVOR= =CEBF '06 SURVIVOR= =August '06 COTM=
LakevilleSSEi is on a distinguished road
Default

Typical BS......interesting though.....
Reply
Old Aug 16, 2007 | 06:54 PM
  #4  
popatim's Avatar
PopaDopaDo
True Car Nut
 
Joined: Jan 2005
Posts: 4,957
Likes: 4
From: NY
popatim is on a distinguished road
Default

I got a ten spot says the culprit works for the hosting company.
Reply
Old Aug 18, 2007 | 12:36 PM
  #5  
13secGTP's Avatar
Senior Member
Posts like a Supercharger
 
Joined: May 2003
Posts: 163
Likes: 0
From: Columbus, OH
13secGTP is on a distinguished road
Default

I got an email from that guy too. Whats funny is it came to my work email which is Whirlpool/Penske/GE specific. And no one knows it......

I have informed Zoom, and he told me to play along to see what else comes up.....
Reply
Old Aug 21, 2007 | 10:11 AM
  #6  
petraman's Avatar
Senior Member
True Car Nut
 
Joined: Jul 2006
Posts: 5,001
Likes: 0
From: Granville, Ohio ~NEBF '07 Survivor~
petraman is on a distinguished road
Default

Are there any updates on this?
Reply
Old Aug 21, 2007 | 06:55 PM
  #7  
McGrath's Avatar
Senior Member
Certified GM nut
 
Joined: May 2005
Posts: 2,155
Likes: 0
From: Wickliffe, Ohio
McGrath is on a distinguished road
Default

Yes could someone pm info as to whats going on here? I can't view the link and I have recently purchased things from ZZP.

Ed
Reply
Old Aug 24, 2007 | 02:49 PM
  #8  
Speedster400's Avatar
Senior Member
Posts like a Turbo
 
Joined: Dec 2006
Posts: 258
Likes: 0
From: NHRA Division 3
Speedster400 is on a distinguished road
Default

So are there any updates? Is safeto order from ZZP again
Reply
Old Aug 31, 2007 | 08:32 PM
  #9  
popatim's Avatar
PopaDopaDo
True Car Nut
 
Joined: Jan 2005
Posts: 4,957
Likes: 4
From: NY
popatim is on a distinguished road
Default

bump for an update if anyones heard anything...
Reply
Old Aug 31, 2007 | 08:43 PM
  #10  
petraman's Avatar
Senior Member
True Car Nut
 
Joined: Jul 2006
Posts: 5,001
Likes: 0
From: Granville, Ohio ~NEBF '07 Survivor~
petraman is on a distinguished road
Default

Originally Posted by Zoomer via CGP
So far I have confirmations from people that do not have their email attached to clubGP who have recieved this spam.

I have also received confirmations from people who have never bought from ZZP or had their email attached to ZZP or the other sites who received the spam.

We're still working on the issue and haven't noticed anything strange log ins, changes to anything on the site, coupon codes added or changed, etc.

We have two separate comanies with teams pouring over our code. Neither has found any holes and the software. While based on OScommerce, our site is so highly modified from the orignal code, that the developer was offended when it was called OScommerce. Being this custom, it would be very difficult to hack into our site based on a hole in the code. We're still looking none-the-less. Even not finding anything, we are adding encription to coupon codes, customer data, and putting SSL? on the admin side. Should take effect shortly.

We have been in contact with helidirect and their software developer. They claim that their code is good. Their code and their site are totally different from ours. They also host with a completely different company. They did find the breach though and it relates to their server. For security reasons, I don't want to go into it further until they have completed the patches. We checked our site and server and we did not have the exploits affecting them.

No info from zipzoomfly, but I'm guessing that was added for email legitimacy.

On our site we are leaning towards a brute force attack stealing our admin password which would give them access to the site. He couldn't change code or get in super deep but he could get email addresses, change coupons, look up people'* order history and edit products. The only thing we ever noticed was that one coupon code and nothing more. Since changing our password, we haven't had issues. As a further step we will probably be changing hosts just in case. I'll post more info as I get it.
I believe it'* OK now
Reply



All times are GMT -4. The time now is 08:10 AM.