Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

newb keep getting hacked need help bad


vqi

Recommended Posts

Chris,

 

You have to update the site to RC2a, then apply the security patches as described in the security forum. Once that is done, install the 5 'must have' security contributions.

 

 

 

Chris

Link to comment
Share on other sites

Chris,

 

You have to update the site to RC2a, then apply the security patches as described in the security forum. Once that is done, install the 5 'must have' security contributions.

 

 

 

Chris

 

 

thanks,

hi im looking for some one to do the update for me , my new web person dosnt no how at all I would think it would be a simpler as i dont have a customer data base .

Link to comment
Share on other sites

Depending on how altered you current store is with lay out changes and added contributions, you might be able to install a brand new updated site and go from there?

cheaper than hiring someone too

Nic

 

Im totaly clueless on this stuff all i KNow is this guy puts in a redirect .httaccess file every night, here is the site let me know what you think about the complicatedniss of it . I can build a computer or a motor but i don know alot about this web design. www.visionquestmultimedia.com I had a company in cali do it for me and they were not great to say the least , and Im not going back there .

Link to comment
Share on other sites

Chris,

 

 

You definitely have an admin vulnerability that needs to be addressed immediately. The site is using highly modified template and if you want to maintain that look and feel, I wouldn't suggest installing a new store and starting from scratch. However, I do suggest you SECURE your current site. Remove the malicious code and anomalous files and then update it manually to a newer version of osCommerce.

 

 

 

Chris

Link to comment
Share on other sites

Chris,

 

 

You definitely have an admin vulnerability that needs to be addressed immediately. The site is using highly modified template and if you want to maintain that look and feel, I wouldn't suggest installing a new store and starting from scratch. However, I do suggest you SECURE your current site. Remove the malicious code and anomalous files and then update it manually to a newer version of osCommerce.

 

 

 

Chris

 

you say admin problem how do i do it ?? I changed the name from admin to another with a differnt password ?

Link to comment
Share on other sites

Good first step.

 

A link to the steps you need to follow to disinfect your site and then to secure it are on my about me pages.

 

If I remember correctly the security patches can be installed on earlier versions as well.

 

Cheaper than hiring someone too!!

 

Cheers

 

G

Need help installing add ons/contributions, cleaning a hacked site or a bespoke development, check my profile

 

Virus Threat Scanner

My Contributions

Basic install answers.

Click here for Contributions / Add Ons.

UK your site.

Site Move.

Basic design info.

 

For links mentioned in old answers that are no longer here follow this link Useful Threads.

 

If this post was useful, click the Like This button over there ======>>>>>.

Link to comment
Share on other sites

Im totaly clueless on this stuff all i KNow is this guy puts in a redirect .httaccess file every night, here is the site let me know what you think about the complicatedniss of it . I can build a computer or a motor but i don know alot about this web design. www.visionquestmultimedia.com I had a company in cali do it for me and they were not great to say the least , and Im not going back there .

Have you changed your FTP password? If they have access to your .htaccess file they may be coming in the same way that you are. You may also want to scan your PC for malware just in case a password stealer is working against you.

Link to comment
Share on other sites

Are you hosting your site yourself?

 

I would for one not use FTP, use SFTP which is part of SSH, alot more secure. And block port 21

 

One way to find out is to check your access file on the server, get the IP of the person and find out whats not secure.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...