428 users online
Register
Log in
Shopping Cart
(0)
Home
Product
Overview
Features
Store demo
Screenshots
Showcase - live shops
Copyright Notice Removal
System Requirements
Roadmap
Contribute
Team Members
License
Downloads
Download nopCommerce
Extensions
Release Notes
Support
Documentation
Forums
Partners
Recommended Hosting
Solution Partners
Become a Partner
Community sponsorship program
My Account
Contacts
Tweet
Home
/
Forums
/
General
/
Security
/
Attempted CSS Attempt?
Attempted CSS Attempt?
Reply
DavidOptrics
Total Posts:
73
Karma:
495
Joined:
11/23/2010
Location:
Canada
PM
Posted:
6 months ago
Quote
I noticed something in our weekly Event Viewer check on our web server.
There is an event viewer warning for an attempt to go to:
hxxp://www.ourwebsitename.com/products/
b]):f===v?c.css(e,d):this.css(d,typeof f===
I wonder if the part in bold is an attempted Cross-Site Scripting attempt. Has anyone else run across it?
The part up to and including products/ IS part of the site. Just the b] forward is the bad part.
- I see that it's the last part of jquery-1.4.min.js
To check, I downloaded jquery-1.4.min.js from jquery.com and compared that last line. It's ALMOST the same.
In NopCommerce"
b]):f===
w
?c.css(e,d):this.css(d,typeof f==="string"?f:f+"px")}});z.jQuery=z.$=c})(window);
From jquery.com:
b]):f===v?c.css(e,d):this.css(d,typeof f==="string"?f:f+"px")}});z.jQuery=z.$=c})(window);
That's the only difference I could find. Not sure why it would be showing up - someone tryint to specifically call it?
thanks
David
0
Please
login or register
to vote for this post.
(click on this box to dismiss)
Expert on LaGarde StoreFront
asp.net (VB) developer, PhotoShop, Graphics
nopSites:
http://www.FirewallShop.com
http://www.BarracudaNetworks.ca
http://www.ManageEngine.ca
http://www.NetworkMonitoring.ca
http://www.NetworkStorageSolutions.com
matchgig
Total Posts:
23
Karma:
133
Joined:
10/7/2010
Location:
United States
PM
Posted:
4 months ago
Quote
I saw the same kind of requests as well. I blocked the ip ranges that these were coming from. Looks like they were isolated to a specific group of individuals since I haven't seen them since.
0
Please
login or register
to vote for this post.
(click on this box to dismiss)
Steve Christensen
Superior IRON-ARTz LLC
Where industry and art collide!
http://www.IRON-ARTz.com