Page 1 of 1

[SOLVED] Opencart forum accounts hacked

Posted: Tue Mar 18, 2025 9:26 pm
by JNeuhoff
We recently received spam messages into our Private Messages inbox from these users:

savioady
loay96azri

Can a forum moderator or administrator please block these accounts?

Re: [SOLVED] Opencart forum accounts hacked

Posted: Thu May 08, 2025 7:45 pm
by OSWorX
JNeuhoff wrote:
Tue Mar 18, 2025 9:26 pm
We recently received spam messages into our Private Messages inbox from these users:
...
Can a forum moderator or administrator please block these accounts?
Seems to be compromised accounts - users are blocked now.

Re: [SOLVED] Opencart forum accounts hacked

Posted: Thu May 08, 2025 11:50 pm
by khnaz35
Should there be a 2FA option enable on the forum as well as we have for marketplace login?

Re: [SOLVED] Opencart forum accounts hacked

Posted: Fri May 09, 2025 12:16 am
by OSWorX
khnaz35 wrote:
Thu May 08, 2025 11:50 pm
Should there be a 2FA option enable on the forum as well as we have for marketplace login?
No, the forum is safe.
It's also not the "fault" of this forum, the "bug" is the user himself.
Because somewhere his login data / credentials are stored because available on an site anywhere ..
It's just a compromised user and the script kiddies are using his data now ..

Re: [SOLVED] Opencart forum accounts hacked

Posted: Fri May 09, 2025 5:34 am
by Johnathan
Technically a 2FA should probably be implemented on the forum (and everywhere) for security purposes, but it's not really a security concern. The worst case scenario is someone's account gets compromised and their posts turn to spam, and then we delete it. They'd lose their post history, but OSWorX is right that it's more of a user issue than a security problem. It happens every once in a while but it's always through someone reusing the same username/password as on other sites.