- Original Poster
- #1
Never thought this would happen to me (probably everyone thinks the same).
A customer rang to say she couldn't make payment with either PayPal or Stripe, so I did a mock purchase. The PayPal page showed FathurFreakz as the heading and couldn't process the payment. I googled this phrase and some posts mentioned it. My opencart website was hacked!
I contacted Vidahost and restored my website to an earlier version. After I logged in, I found several new admin users in this name. Delete them. Then I saw my PayPal plugin was setting up a hacker's account. Uninstall.
However, to my shock, using any username or password (such as 1 and 1) can access the back office. My admin URL is domain/myownURL/, not /admin/, but I wonder what codes the hacker has changed to make any combination of username or password can gain access?
Still waiting for Vidahost to offer some help. Is there anybody who knows about this issue? Do you offer any professional service to make my Opencart more secure? Thank you.
A customer rang to say she couldn't make payment with either PayPal or Stripe, so I did a mock purchase. The PayPal page showed FathurFreakz as the heading and couldn't process the payment. I googled this phrase and some posts mentioned it. My opencart website was hacked!
I contacted Vidahost and restored my website to an earlier version. After I logged in, I found several new admin users in this name. Delete them. Then I saw my PayPal plugin was setting up a hacker's account. Uninstall.
However, to my shock, using any username or password (such as 1 and 1) can access the back office. My admin URL is domain/myownURL/, not /admin/, but I wonder what codes the hacker has changed to make any combination of username or password can gain access?
Still waiting for Vidahost to offer some help. Is there anybody who knows about this issue? Do you offer any professional service to make my Opencart more secure? Thank you.