Jump to content

Hacked? My site randomly redirects to a malicious site when clicking on any random link


Recommended Posts

My site has been hacked?

 

it seems like a conditional redirect hack, but I'm not too certain. At random times when clicking on any links it redirects the customer to an adult site. It comes and goes, so it is hard to reproduce the issue. I have spoken to the hosting company, and even they could not trigger the issue and had been of no help thus far. And I've scoured the internet and forums looking for possible solutions.

 

Since the attack, I have changed all passwords - ftp, database, prestashop.

 

I have tried to look at all the possible files it may have been modified including. htaccess and I still have no luck. Any advice would be greatly appreicated.

 

 

 

Link to comment
Share on other sites

I don't think it is localized. the customer that notified me told me on both his home desktop, smartphone and his son's smartphone all came up. My manager who tried it at his own home also had the same result on his phone and tablet. They also notified me that it didn't always redirect from the same link. I have personally tried to pull the same results on all major browser on the desktop including my own smartphone but did not connect me at all.

Link to comment
Share on other sites

I was able to get redirected once after clicking the airsoft guns link from the menu.  However it only occurred once, and I tried many different links and pages and it never occurred again. 

 

So I was not able to catch any of the http responses to see where the redirect was occurring.  You'll need to trace if it is a bit of javascript code being executed, or something within the core coding

Link to comment
Share on other sites

I do have a backup from a few months back. We haven't decided yet if it is better to wipe everything and upload the backup. 

It still would be good know for future referencing should it ever ( hopefully never ) happen again.

 

In terms of tracing, I'm not sure how to do it. I've tried looking through many of the the possible main core files it may have infected, but i'm literally in the dark.

Link to comment
Share on other sites

if you have recent anti-virus on your computer then download using ftp your files to see if anti-virus detects bad file.  this typically works.  look in /js/ folders first for any updates.  check that you have 755 folders and 644 files (.665 .htaccess)...good luck!

 

in the future you can use this module to email you when file/file date/file permissions change.

http://www.prestashop.com/forums/topic/303132-module-prestavault-malware-trojan-virus-protection/

  • Like 1
Link to comment
Share on other sites

×
×
  • Create New...