Post by Bobbio999 » Wed Nov 03, 2021 5:46 pm

Hi all,

We are running on OC Version 2.1.0.1

We seem to get re-infected with the same credit card malware every few days on our VPS. We have Securi who will spot and clean it (they say it's infecting the oc_setting.value in the database), and we can roll back the DB every time, which also removes it, but we need a permanent solution.

We are a 1 man business looking for the most cost effective solution. We have changed all the CPanel passwords but that doesn't work. May I ask, will a firewall fix this, or is it time to upgrade to Version 3? Are there any developers who can give us costings / timings for an upgrade. We have no themes, and just the usual plug in's for Payment, Volume Discounts etc

Kind Regards
Rob

New member

Posts

Joined
Thu Apr 16, 2015 11:19 pm

Post by thekrotek » Wed Nov 03, 2021 6:13 pm

I can check your server for backdoors and malware, done this multiple times. Send me an email or message in Skype and we'll discuss the details.

Professional OpenCart extensions, support and custom work.
Contact me via email or Skype by support@thekrotek.com


User avatar
Expert Member

Posts

Joined
Sun Jul 03, 2016 12:24 am


Post by paulfeakins » Wed Nov 03, 2021 6:34 pm

Contact Astra, they'll do an audit with a load of recommendations for a developer such as ourselves to implement.

Alternatively we could do a rebuild for you as listed here: https://www.antropy.co.uk/services/ecommerce-business

UK OpenCart Hosting | OpenCart Audits | OpenCart Support - please email info@antropy.co.uk


User avatar
Legendary Member

Posts

Joined
Mon Aug 22, 2011 11:01 pm
Location - London Gatwick, United Kingdom

Post by Bobbio999 » Wed Nov 03, 2021 7:49 pm

Quick update for anyone with the same issue, we now believe the infection is via the Google Analytics plug in.

New member

Posts

Joined
Thu Apr 16, 2015 11:19 pm

Post by OSWorX » Wed Nov 03, 2021 8:53 pm

Bobbio999 wrote:
Wed Nov 03, 2021 7:49 pm
Quick update for anyone with the same issue, we now believe the infection is via the Google Analytics plug in.
Basically this is a "core" module - add only the code and save.
It's not an extra extension - or what are you using?

Full Stack Web Developer :: Dedicated OpenCart Development & Support DACH Region
Contact for Custom Work / Fast Support.


User avatar
Administrator

Posts

Joined
Mon Jan 11, 2010 10:52 pm
Location - Austria

Post by Bobbio999 » Wed Nov 03, 2021 10:13 pm

Yes we have disabled the core module for Google analytics (and the <script> provided by Google therein) and the infections appear to have stopped.

New member

Posts

Joined
Thu Apr 16, 2015 11:19 pm

User avatar
Expert Member

Posts

Joined
Tue Jul 17, 2012 10:35 pm
Location - România

Post by OSWorX » Wed Nov 03, 2021 10:56 pm

Bobbio999 wrote:
Wed Nov 03, 2021 10:13 pm
Yes we have disabled the core module for Google analytics (and the <script> provided by Google therein) and the infections appear to have stopped.
Never heard something like this before.
From where do you have this code and could you post here this snippet (remove sensitive data before).

Full Stack Web Developer :: Dedicated OpenCart Development & Support DACH Region
Contact for Custom Work / Fast Support.


User avatar
Administrator

Posts

Joined
Mon Jan 11, 2010 10:52 pm
Location - Austria

Post by Bobbio999 » Thu Nov 04, 2021 12:08 am

In the Analytics section of Admin, we deleted the Google <script> and disabled this function. The script from Google must have been provided several years ago now. (we didn't keep a copy of it unfortunately).

Analytics List
Analytics Name Status Action
Google Analytics Disabled

New member

Posts

Joined
Thu Apr 16, 2015 11:19 pm

Post by OSWorX » Thu Nov 04, 2021 12:38 am

Bobbio999 wrote:
Thu Nov 04, 2021 12:08 am
In the Analytics section of Admin, we deleted the Google <script> and disabled this function. The script from Google must have been provided several years ago now. (we didn't keep a copy of it unfortunately).

Analytics List
Analytics Name Status Action
Google Analytics Disabled
Well, you are using a very old version of OpenCart .. may work, but I guess your php version is also outdated (you should update at least the php version to 7.3.x which requires also to update 1 script of OpenCart).
Beside this, the code provided from Google is not able to add something else - so the person who pasted it, made some ? ?
See: https://developers.google.com/analytics ... nalyticsjs

Full Stack Web Developer :: Dedicated OpenCart Development & Support DACH Region
Contact for Custom Work / Fast Support.


User avatar
Administrator

Posts

Joined
Mon Jan 11, 2010 10:52 pm
Location - Austria

Post by EvolveWebHosting » Fri Nov 05, 2021 9:10 pm

Bobbio999 wrote:
Wed Nov 03, 2021 5:46 pm
Hi all,

We are running on OC Version 2.1.0.1

We seem to get re-infected with the same credit card malware every few days on our VPS. We have Securi who will spot and clean it (they say it's infecting the oc_setting.value in the database), and we can roll back the DB every time, which also removes it, but we need a permanent solution.

We are a 1 man business looking for the most cost effective solution. We have changed all the CPanel passwords but that doesn't work. May I ask, will a firewall fix this, or is it time to upgrade to Version 3? Are there any developers who can give us costings / timings for an upgrade. We have no themes, and just the usual plug in's for Payment, Volume Discounts etc

Kind Regards
Rob
Isn't a component of Sucuri's service a firewall? If so, they should have been stopping this, not detecting you and telling you it was getting infected over and over.

If you want to try Astra (and anyone else reading this), contact us here for a 2 week trial: https://core.evolvewebhost.com/contact.php

If you like it, you can purchase a license (our pricing is the lowest I've seen). Otherwise, we'll disconnect you from the Astra service. No hassles or headaches.

Personally, I do recommend using a newer version of Opencart although not all releases are great. For example, I think 2.3.0.2 was the best of the 2.x branch and I'd say 3.0.3.7 or 3.0.3.8 are the two better versions of the 3.x branch. A release like 4.0.0.0_b in 2017 is very odd to me and I wouldn't use a release like that.

Opencart Hosting Plans, Domain Registration, Microsoft and Google Email and More
Visit our website for great deals and most importantly, fast and friendly support - www.evolvewebhosting.com


User avatar
Active Member

Posts

Joined
Fri Mar 27, 2015 11:13 pm
Location - Denver, Colorado, USA
Who is online

Users browsing this forum: No registered users and 4 guests