griz99 Posted July 8, 2014 Share Posted July 8, 2014 Hello, I have just reinstalled the prestashop on one of my domains http://shoptemplate.net/ after a few days, I got hacked, before this, my database was deleted. I don't know how... So I am wondering if it is a known vulnerability and if I can do anything about it, it is very disturbing. I have deleted old ftp data and account, created a new one (generated password) generated random database and username, random password. If anyone has any advice or maybe knows what I can do to stop these attacks. Thanks, Alex. Link to comment Share on other sites More sharing options...
dioniz Posted July 8, 2014 Share Posted July 8, 2014 Check your computer for viruses,trojans... with good antivirus and tell us if it found something Link to comment Share on other sites More sharing options...
griz99 Posted July 8, 2014 Author Share Posted July 8, 2014 I just checked, it seems all domains on the hosting account have the same page, does this say anything ? Link to comment Share on other sites More sharing options...
dioniz Posted July 8, 2014 Share Posted July 8, 2014 Can you elaborate a bit more, what do you mean by same page? Link to comment Share on other sites More sharing options...
griz99 Posted July 8, 2014 Author Share Posted July 8, 2014 www.strong.ro this site is hosted on the same hosting account, it wasn't using any CMS, and it seems to have the same index page. Also other domains hosted there seem to be have the same problem. It is a payed host from GoDaddy, shared linux plan. Link to comment Share on other sites More sharing options...
griz99 Posted July 8, 2014 Author Share Posted July 8, 2014 I think the problem might have been that one of the domains had wordpress installed on it and it probably wasn't updated properly lately, they might have hacked that and that's how probably they got to all other domains, although it is pretty nasty if they can do that. I am no expert, I just purchased Bit Defender and scanned the PC, no problems were found. Link to comment Share on other sites More sharing options...
vekia Posted July 8, 2014 Share Posted July 8, 2014 1) where you website is hosted? 2) do you use some other cms on your hosting account? Link to comment Share on other sites More sharing options...
griz99 Posted July 8, 2014 Author Share Posted July 8, 2014 1) - The website is hosted at GoDaddy 2) - There was a site that used Wordpress, I deleted everything now, I am thinking that's how they got in, through wordpress because it wasn't updated in some time. Link to comment Share on other sites More sharing options...
griz99 Posted July 8, 2014 Author Share Posted July 8, 2014 I reinstalled, removed the other CMS, changed passwords, scanned PC, removed databases, deleted all files on host. Now I am waiting to see if it will happen again. 1 Link to comment Share on other sites More sharing options...
Recommended Posts