Jump to content

Prestashop 1.7.8.6 - hacket??


966972_1508426717

Recommended Posts

After you recover (restore?)  you can use my module written when my 1.4 shop got hacked.  Once installed it will monitor your shop files and detect 'any' change rnd send an alert.  You can then action by:  restoring the file from vault |  commit trusted change to vault.  

https://prestaheroes.com/collections/all-modules/products/prestavault-malware-trojan-virus-protection

immunavy is good to have on your hosting, for plesk but may be one for cpanel.

 

What to do immediately

Change all passwords

  • PrestaShop back office users
  • FTP / SFTP
  • Hosting panel
  • Database user
  • Scan for modified files
  • Compare timestamps vs backups

Look for:

  • Unexpected .php files
  • PHP code inside /img, /upload, /pdf
  • Modified .htaccess
  • Lock down permissions
  • Files: 644
  • Folders: 755

Disable unused modules

  • Especially old or unmaintained ones
  • Remove modules you “might use later”

Note: AI is excellent in reading and reporting log issues.

Check logs

Access log

Error log

ModSecurity log (if enabled)

Look for POST requests to upload endpoints

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...