Well, it could be the same with Opencart Sites, when Mods areBad extensions now main source of Magento hacks: a solution!
downloaded from shady Places. That's always a Risk, even with
'regular' Extensions, free or paid. We experienced such a Case
with a Crypto-Miner Code on the OC Extension Section already,
not so long ago.
But it always potentially dangerous, if someone, not familiar,
tries to modify a Car-Engine, or some Software. One just has
to be aware of that, and act accordingly. Access- and Error Logs
should be checked on a daily schedule, to find out, who's accessing
the Shop Site, and what 'Access Commands' are used for such. It's
Part of the Job, to make sure, like anywhere else in real life ...

---
After locking out ~220 (OC Sites) IP Ranges so far, like:
Code: Select all
deny from 213.163.93.
deny from 213.251.
deny from 216.
800 HTTP_REFERER - HTTP_USER_AGENT - REQUEST URL Lines, like:
Code: Select all
RewriteCond %{HTTP_REFERER} ^.rambler\.ru [NC,OR]
RewriteCond %{HTTP_REFERER} ^.rv\.ua [NC,OR]
RewriteCond %{HTTP_REFERER} ^.dontknow\.me [NC,OR]
RewriteCond %{HTTP:PROXY_CONNECTION} !^$ [NC,OR]
RewriteCond %{HTTP:XPROXY_CONNECTION} !^$ [NC,OR]
RewriteCond %{HTTP:HTTP_PC_REMOTE_ADDR} !^$ [NC,OR]
RewriteCond %{HTTP:HTTP_CLIENT_IP} !^$ [NC,OR]
RewriteCond %{HTTP_USER_AGENT} ^WebCapture [NC,OR]
RewriteCond %{HTTP_USER_AGENT} ^Alexibot [NC,OR]
RewriteCond %{HTTP_USER_AGENT} ^asterias [NC,OR]
RewriteCond %{HTTP_USER_AGENT} ^Zeus [NC,OR]
RewriteCond %{HTTP_USER_AGENT} ^Zeus\.*Webster [NC,OR]
to Vegas:

It add's a little more to Security, and to not beeing targeted by those,
only adding to Traffic, for not one good reason at all.

Ernie
---
Attachments
security_log.jpg (201.89 KiB) Viewed 1359 times
I don't use Forum Mail, to reach me, contact: jti@jacob.ch
-
Server Q & A Basic Information on Code + Settings
http://www.everyauction.info/serverinfo.html
Demoversion OpenCart LIGHT v.1.5.6.5
http://www.jti.li/shop/
1'400+ FREE OC Extensions - from OC v.1.5.x up,
on the world's largest OC-related Github Site: https://github.com/IP-CAM
-
Credit Card, bank account and personal data are on the top of their list.
At least, it is our responsibility when operating Webshops, to force the security.
Do everything we can, to make these stores as safe as possible.
That starts witht the provider/hoster: do not use any 'free' offer.
Second, try to avoid cheap offers, you may share the server with thousands of others (which can lead to be a victim if another website on the same server is hacked and is infecting all others).
Third, do not use extensions, modules, templates NOT from official sites, a result may such: viewtopic.php?f=199&t=211655&p=754807
Just to mention the most made mistakes.
Custom Development | Individuelle Entwicklung | Support & Bugfixes
Jim
Middle Caicos, Turks and Caicos Islands
enable me to make use of things like fail2ban.
And I like to know, who's trying to give me a hard time.

It's interesting to see, what they use on Code, to possibly get in ...

I use Razztech's free 301 Redirect Pages for OC:
https://www.opencart.com/index.php?rout ... n_id=25864
and Exife's (gone ...) nice OC Security Module, to get & have control,
without spending much time, except for frequently adding some IP's
to my ROOT .htaccess File manually too...

Ernie
PS: Lucky Me, to still use old things, they already exist

---
PS: I have some Security-related OC Mod Downloads on Github,
just in case:
https://github.com/IP-CAM?utf8=✓&tab=re ... q=security
---
Attachments
oc_1565_security.jpg (136.05 KiB) Viewed 1211 times
I don't use Forum Mail, to reach me, contact: jti@jacob.ch
-
Server Q & A Basic Information on Code + Settings
http://www.everyauction.info/serverinfo.html
Demoversion OpenCart LIGHT v.1.5.6.5
http://www.jti.li/shop/
1'400+ FREE OC Extensions - from OC v.1.5.x up,
on the world's largest OC-related Github Site: https://github.com/IP-CAM
-
Jim
Middle Caicos, Turks and Caicos Islands
That's correct, shared with more than 1'000 others, using the same IP ...You must be on shared hosting ...

It's much cheaper, and more 'representative', when it comes to compare
Performance with other OC Sites, most likely also using shared hosting.

One only has to make sure, to get the best Hoster in Town, then, one has no problem.
And beeing up to 100% Siteload on GTMetrix already, only Yslow could possibly still go
up a little more, but I'm satisfied with 92%, for the price I pay, to keep my ~40 different
active URL's in one place. It's less than a BigMac Menu with a large Coke per Month,
to be part of the Game, top secure, and without a single compromise, or even some
Sub-Hosters in between ...

Ernie
---
Image Link:
download/file.php?mode=view&id=37093&si ... 5739c99840
Attachments
hostpoint_first_class_swiss_hosting.jpg (117.67 KiB) Viewed 1113 times
I don't use Forum Mail, to reach me, contact: jti@jacob.ch
-
Server Q & A Basic Information on Code + Settings
http://www.everyauction.info/serverinfo.html
Demoversion OpenCart LIGHT v.1.5.6.5
http://www.jti.li/shop/
1'400+ FREE OC Extensions - from OC v.1.5.x up,
on the world's largest OC-related Github Site: https://github.com/IP-CAM
-
Users browsing this forum: No registered users and 1 guest