xentr_theme_editor

  • Please do not post any links until you have 3 posts as they will automatically be rejected to prevent SPAM. Many words are also blocked due to being used in SPAM Messages. Thanks!

Canada Computers site possibly compromised

chrisk

Folding Captain
Joined
Jul 12, 2008
Messages
7,739
Reaction score
150
Location
GTA, Ontario
xentr_thread_starter
Hey folks;
Lots of people here shop at Canada Computers so I figured I would point you towards this Reddit thread:


If accurate, there was a script that was spoofing a legit website and credit card info, ordering addresses, etc would have been logged when shopping on the Canada Computers website.

Check out the thread and decide for yourself. I'm not an expert in this stuff at all, I suspect some folks here would have more to say about this than I.
 
That's disturbing. Thanks for the head's up!

I didn't make it all the way through the thread, has there been any kind of response from Canada Computers?

edit: Don't quote me, but it looks like it might have been active sometime early december and was only removed today.
 
xentr_thread_starter
That's disturbing. Thanks for the head's up!

I didn't make it all the way through the thread, has there been any kind of response from Canada Computers?

edit: Don't quote me, but it looks like it might have been active sometime early december and was only removed today.
No response. Apparently the OP had placed 2 tickets which were closed. That's when they went public.

And yeah, only removed after the security consultant in the thread reached out to ask about it....
 
Ouch… I will follow for updates. Need to check when I last ordered…or would it have access to everything historic as well?
 
xentr_thread_starter
Ouch… I will follow for updates. Need to check when I last ordered…or would it have access to everything historic as well?
What's been reported so far as I can tell we're transactions done during the exploit. It essentially worked as a keylogger.
 
I was reading through this earlier tonight as well, not sure if there's really any valid proof of people seeing fraudulent transactions, but that risk is there for all the online shopping most of us do now. As usual, keep an eye on your bills or even daily/weekly since most cards/banks show transactions pretty quick now.
 
Ouch… I will follow for updates. Need to check when I last ordered…or would it have access to everything historic as well?
What's been reported so far as I can tell we're transactions done during the exploit. It essentially worked as a keylogger.

Yeah reading through the thread, it looks like it's not a case of them having their database hacked, it's a case of somebody recording the CC creds when entered so it's only applicable to transactions during that time period.
 
xentr_thread_starter
Yeah it's actually not sure if that keylogger script is what they are talking about either. While I understand that they need to have tight messaging in situations like this, seems like they aren't being forthcoming on the info to me as the original Reddit post mentioned the compromised script was there for a longer period of time.

Let's see.
 

Latest posts

Back
Top