Jump to content

Payment was replaced by Hacker


qiqiy_888

Recommended Posts

  • razaro changed the title to Payment was replaced by Hacker

There is a solution, (use google translate if needed)

this script removes main hack files but it also gives you list of edited files that may also have some encrypted code (mostly at end of files).

You need to open those files and remove code or if uncertain replace with original files.

 

Also explained here bit more

https://www.mediacom87.fr/en/how-to-prevent-hacking-on-prestashop-and-thirty-bees/

  • Like 4
Link to comment
Share on other sites

10 hours ago, razaro said:

There is a solution, (use google translate if needed)

this script removes main hack files but it also gives you list of edited files that may also have some encrypted code (mostly at end of files).

You need to open those files and remove code or if uncertain replace with original files.

 

Also explained here bit more

https://www.mediacom87.fr/en/how-to-prevent-hacking-on-prestashop-and-thirty-bees/

Thank you so much, i will check this.

Link to comment
Share on other sites

12 hours ago, GIO.D.P.M. said:

Hello.

I have the same problem.

  I can't see my payment methods.

What can I do to fix it?

Screenshot (4).png

@razaro post is helpful. but i just change the tpl file at theme files : order-payment.tpl

i changed the id="HOOK_PAYMENT"  to id="HOOK_PAYMENT_*******"    the payment show now

i am not sure it can fix the problem, but now, our customers can see the payment method. 

Link to comment
Share on other sites

19 hours ago, c64girl said:

UnInstall the module or delete IT front FTP. Password the catalog od prestashop using cpanel or diretadmin. Use migration tool to copy orderem,products,users,static pages and use newer prestashop.

Thank you for your suggestion

Link to comment
Share on other sites

@qiqiy_888

Note that changing code in that file have no effect on hackers in general. They used code placed somewhere deep in you root folder and on multiple places that when called copies complete payment.tpl  and injects fake form. 

You should also check your hosting, if you are on Plesk there is ImunifyAV or 360 or maybe Clam Anti-Virus, with them you can scan files from hosting. Cleaner.php linked script, do find most of issues but some could slip.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...