Post by spicyspirit » Wed May 06, 2015 4:23 am

My Opencart 1.5.6 website has recently been attacked and there are many "wp-" folders showing in the root of the FTP.

See screenshot attached.

I've been manually removing newly added spam folders every day.

Upgrading the site is not possible right now. I wonder if there is any way to stop this folders from coming in?

Thank you.

Attachments

wpfolders.jpg

wpfolders.jpg (62.25 KiB) Viewed 1090 times


Newbie

Posts

Joined
Sun Apr 06, 2014 5:08 am

Post by marvmen21 » Wed May 06, 2015 5:35 am

That looks like wordpress files. Change your hosting account passwords, change all your ftp passwords. Contact your host, they can help you track the hackers ip and block it.

Regards,

Marvin M

You want to thank me for my time! :) Click here to donate


Active Member

Posts

Joined
Tue Nov 09, 2010 4:54 am

Post by artcore » Wed May 06, 2015 2:22 pm

You have some custom pages outside the OC framework including a contact form. These should be carefully tested for security holes. It's unclear if you have a WP installation in that /blog folder. WP(or plugins) is quite vulnerable as new exploits are discovered every time (query_args function recently). Update all the plugins and core!
Your server is not protected against POODLE, SSL2.0 and more. Tell your host to do his homework.
Quick test, you should examine the logs against the creation time of those folders to see if there's a clue as to how they did it.
Changing passwords is a good idea but will not help if your scripts are unsafe.

Attn: I no longer provide OpenCart extensions, nor future support - this includes forum posts.
Reason: OpenCart version 3+ ;D

Thanks!


User avatar
Active Member

Posts

Joined
Tue Jul 09, 2013 4:13 am
Location - The Netherlands

Post by Dhaupin » Thu May 07, 2015 4:25 am

Hmm it looks like wp-frle and wp-coment (mis-spelled) have been in there since march.

If you are sure its not because of a vulnerability, or a weak password, then the next step is to tell your host to install a cage/jail/isolation for the multi-tenant servers. This prevents cross account file drops and loads of other things from happening if some other customers install becomes exploited. Many hosts are just amateur resellers with a VPS, they dont really understand what they are doing when it comes to operating a solid server, and they dont run security audits or check customers files for malware.

https://creadev.org | support@creadev.org - Opencart Extensions, Integrations, & Development. Made in the USA.


User avatar
Active Member

Posts

Joined
Tue May 13, 2014 3:45 am
Location - PA

Post by spicyspirit » Fri May 08, 2015 2:00 am

Thank you all for your kind suggestions. Password change didn't work. I'm contacting my host now and see what they can do. Thanks again!

Newbie

Posts

Joined
Sun Apr 06, 2014 5:08 am
Who is online

Users browsing this forum: No registered users and 117 guests