Page 1 of 1

Help! Site constantly being hacked :-\

Posted: Fri Dec 13, 2019 4:53 pm
by Nordikota
Hi. Site is OC3.0.3.2 running Journal3

Our site has been hacked somehow and a number of files (Index.php) have been added that redirect customers to Spam sites. .htaccess files have been renamed. I've been through every directory and manually removed the files, updated .htaccess to disallow access, changed the file attributes to remove write access and changed all Admin & FTP passwords.

2 days later the site was hacked again. So I did the same thing again all over again.

2 days later the site was hacked again. I've just finished cleaning it for a 3rd time

Can anyone suggest how I can stop this as it's getting painful :'(

Re: Help! Site constantly being hacked :-\

Posted: Fri Dec 13, 2019 4:59 pm
by letxobnav
checked your logs?

Re: Help! Site constantly being hacked :-\

Posted: Fri Dec 13, 2019 5:29 pm
by Nordikota
The error log? I wouldn't know what to look for ???

Re: Help! Site constantly being hacked :-\

Posted: Fri Dec 13, 2019 5:41 pm
by thekrotek
Looks like you have a backdoor somewhere on your server. If you can't find it, I can do it for you. Drop me an email or send a message in Skype and we'll discuss the matter.

Re: Help! Site constantly being hacked :-\

Posted: Fri Dec 13, 2019 6:45 pm
by Nordikota
@thekrotek - email sent. Thanks!

Re: Help! Site constantly being hacked :-\

Posted: Fri Dec 13, 2019 6:55 pm
by paulfeakins
Contact Astra ASAP, they have sorted this out for many OC users we know.

Re: Help! Site constantly being hacked :-\

Posted: Fri Dec 13, 2019 7:09 pm
by wrick0
Make sure you are not running any pirated extensions.

Make sure you are not running wordpress on the same host.

Make sure modsecurity is active on your server, as well as fail2ban and some antivirus i recommend ImunifyAV.


Probably the best method is to get another VPS/host and secure that properly (use plesk it can do most for you).

Then move your site over to that new server (after scanning it with antivirus)

If you want to be completely sure your website is clean, rebuild it completely

Re: Help! Site constantly being hacked :-\

Posted: Fri Dec 13, 2019 11:13 pm
by letxobnav
The error log? I wouldn't know what to look for
your server access log, useless to keep mopping the floor when you have no clue which faucet you left running.

Re: Help! Site constantly being hacked :-\

Posted: Wed May 17, 2023 5:10 pm
by nureddin21
wrick0 wrote:
Fri Dec 13, 2019 7:09 pm

Make sure you are not running wordpress on the same host.

I have the same situation and my site (opencart) has been hacked more than once.

I have a wordpress site installed on the same hosting (hostinger).

I would like to ask you, what is the relationship of WordPress, even though it is independent with its files and there is a file protection system?

Re: Help! Site constantly being hacked :-\

Posted: Wed May 17, 2023 6:17 pm
by paulfeakins
nureddin21 wrote:
Wed May 17, 2023 5:10 pm
I would like to ask you, what is the relationship of WordPress, even though it is independent with its files and there is a file protection system?
WordPress gets hacked all the time because of its popularity. If it's in the same account as OpenCart then a hack gives them access to everything.