TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Another Victim of the Magecart Assault Emerges: Newegg

79 点作者 GraemeL超过 6 年前

11 条评论

chrissnell超过 6 年前
How did the attackers get the JS onto the cart page? That's the interesting part to me that the article leaves out. They managed to break into a PCI-compliant website that presumably has significant defenses and auditing in place.
评论 #18024868 未加载
评论 #18024708 未加载
评论 #18025726 未加载
评论 #18025880 未加载
alyandon超过 6 年前
Lovely. I made a purchase recently with NewEgg but at least it was with a previously stored credit card so hopefully I&#x27;m not impacted by this.<p>However, I am disappointed that NewEgg hasn&#x27;t made any sort of official announcement yet.
评论 #18027774 未加载
评论 #18027147 未加载
评论 #18025826 未加载
评论 #18025979 未加载
Usu超过 6 年前
This breach has reminded me of this pretty great article: <a href="https:&#x2F;&#x2F;hackernoon.com&#x2F;im-harvesting-credit-card-numbers-and-passwords-from-your-site-here-s-how-9a8cb347c5b5" rel="nofollow">https:&#x2F;&#x2F;hackernoon.com&#x2F;im-harvesting-credit-card-numbers-and...</a>
mwigdahl超过 6 年前
They are just now (around 11:10 CDT 9&#x2F;19) sending out notification emails to customers. At the moment they don&#x27;t even seem to know what accounts were affected.
gregpilling超过 6 年前
I am surprised that there is no automated alert to tell the webmaster that his code has changed on his website. Especially on the payments page!<p>With 50,000,000 users a month, surely they have a whole team working on checkout, all the time?
评论 #18024786 未加载
评论 #18024758 未加载
anontechworker超过 6 年前
For a website with so many visitors and transactions, I’m surprised this API call never threw enough errors for them to see in logging. I will admit that JS logging can be messy because of all the different environments but after some time I would have hoped this would have been caught.
raverbashing超过 6 年前
So how come is Comodo selling certificates to domain squatters? This seems to be one sore point here.
评论 #18025258 未加载
crunchlibrarian超过 6 年前
I had a conversation two days ago with the CTO of a very large company you&#x27;ve definitely heard of who said &quot;we don&#x27;t need to worry about our website security, we have a firewall and SSL&quot;<p>I think these types of attacks are vastly underreported, if anything.
adreamingsoul超过 6 年前
Wow, I also made a purchase within that time window. Except, I used PayPal during Checkout.
BeetleB超过 6 年前
Damn. I made a purchase in that time period. I rarely buy anything from them, but it had to happen in that interval!<p>I paid with Paypal. I assume I&#x27;m not affected?
评论 #18026093 未加载
评论 #18026399 未加载
zxin超过 6 年前
This all could have been prevented if they had a Content Security Policy.
评论 #18025313 未加载