Jump to content

Prestashop hacked

Recommended Posts

My prestashop site has been hacked and a bunch of random links have appeared on the home page for viagra..... nice.


I had to reset my password so I assume they managed to get in via the prestashop install not the Server.

I've changed my passwords the admin url i re-generated the htaccess file and I'm currently checking the server for malware/virus'.

I've searched the mysql database for the term http:// on its own, as well as the full url of the links i want removed (which i won't post here for obvious reasons).

I've also downloaded and searched the whole public_html folder and searched through that.


I can't seem to find where the links are coming from. They only appear on the home page of the site any ideas and help very welcome


Many Thanks


Link to comment
Share on other sites

There are some malwares that sit on your local computer and add ads to any website, those are often confused with a real server side hacks.


Can you post a link to the site? did you see if any files on the server have been touched?

Link to comment
Share on other sites


I have contacted my host, they are checking into it as well but as i say I can't see any obvious malware myself. My public_html is set to 750.



I've checked the site on two different computers and the links appear on both so i believe its on the website.

The site url is https://www.mypinkelephant.co.uk The links appear just before the closing body tag.


I've also disabled and re-enabled all the plugins the site uses but the links remain and switched to the standard theme but to no avail.


I was originally called to look at the site after a customer complained that they couldn't connect to paypal. Paypal plugin seems fine but i guess it might somehow be connected.

Link to comment
Share on other sites

They are there yes, after the <div id="page"> closes and before the </body> have tested this on 2 different Macs in chrome FF safari and opera.

the links float to the right of the slider if your monitor is wide enough.

Link to comment
Share on other sites

Copied from firebug

<div id="page">.....</div>

<a href="http://genericviagraonlinenvi.com">generic viagra</a>

<a href="http://mypinkelephant.co.uk/ylobflorenenceombudsman/the-journal-of-bone-and-joint-surgery-inc-sash.html">The journal of bone and joint surgery, inc</a>


appears on my android phone as well

Link to comment
Share on other sites

thats what i see


The code


<!-- MODULE JQuerySlider Galery -->
<!-- www.tiendasvirtuales.com.ve -->
<script type="text/javascript" src="/modules/jqueryslider/js/easySlider1.5.js"></script>
<link rel="stylesheet" type="text/css" href="/modules/jqueryslider/css/jqueryslider.css" />
<div id="container">
 <div id="slider">

	    <a href='/category.php?id_category=1'><img src='/modules/jqueryslider/en0.jpg'alt="" class="active" /></a>

	    <a href='/category.php?id_category=1'><img src='/modules/jqueryslider/en1.jpg'alt="" class="active" /></a>

	    <a href='/category.php?id_category=1'><img src='/modules/jqueryslider/en2.jpg'alt="" class="active" /></a>

	    <a href='/category.php?id_category=1'><img src='/modules/jqueryslider/en3.jpg'alt="" class="active" /></a>

<script type='text/javascript' id='slider'>
$(function() {
<!-- /MODULE JQuerySlider Galery -->

<!-- Module Editorial -->
<div id="editorial_block_center" class="editorial_block">

<h1>Welcome to My Pink Elephant</h1>
 <h2>My Pink Elephant offers quality goods hand sourced from the far east.</h2>
 <div class="rte"><p>
Here you will find Shawls, Trinket boxes, jewellery and beautiful hand crafted ornaments.
All of the products found at My Pink Elephant are fair trade .
<p> If you have any questions or queries please contact us <a href="/contact-us">here</a> or email us at:
<a href="mailto:paula@mypinkelephant.co.uk">paula@mypinkelephant.co.uk</a>
<p>or call</p>
<h3>07943868211 </h3>
<!-- /Module Editorial -->

</div> <!--heightspacer-->
<!-- Right -->
   <div id="BottomHook" class="column">

<div class="advertising_block">
<p><a href="https://www.mypinkelephant.co.uk/modules/paypal/about.php" rel="nofollow"><img src="/modules/paypal/img/vertical_US_large.png" alt="PayPal" title="Pay with PayPal" /></a></p>
</div><!-- wozia custom module : SocialMod -->
<div id="socialmod" class="block">
<h4> Follow us </h4>
  <ul id="social">

  <li class="button facebook">
  <a href="http://www.facebook.com/pages/My-Pink-Elephant/153659358068842" target="_blank" title="Our Facebook Profile"> </a>

  <li class="button linkedin">
  <a href=" http://uk.linkedin.com/pub/paula-martin/2a/a65/750 " target="_blank" title="Our LinkedIn Profile"> </a>

  <li class="button twitter">
  <a href="https://twitter.com/#!/MyPinkElephant_" target="_blank" title="Our Tweets"> </a>

<!-- /wozia custom module --><!-- Lastest post -->
<!-- /Lastest post -->
<!-- Blog categories -->
<!-- /Blog categories -->
<!-- Blog tags -->
<!-- /Blog tags -->

<div class="clear"></div>
<!-- Footer -->
  <div id="footer">
  <!-- Block footer links module -->
<div class="blockfooterlinks" id="blockfooterlinks">
  <li class="first_item"><a href="http://www.mypinkelephant.co.uk/content/1-delivery">Delivery</a></li>
    <li class="item"><a href="http://www.mypinkelephant.co.uk/content/2-accessibility">Accessibility</a></li>
    <li class="last_item"><a href="http://www.mypinkelephant.co.uk/content/3-terms-and-conditions">Terms and Conditions</a></li>
<!-- /Block footer links module -->
  <div style="text-align:right; margin: 0 auto; width: 755px; "> <a target="_blank" href="http://www.clockworkmoggy.com"> <img style="padding:0 10px 0 0; margin:0; float: right;" src="http://www.clockworkmoggy.com/images/WebSignatureW.png" alt="Clockwork Moggy"> </a> <p style="padding:0 5px 2px; margin:0;font-size:12px; float: right;">Designed By </p> </div>



Link to comment
Share on other sites

Thanks Bill, I'm guessing that it must be my network.

I'm the technical support for my family and friends so people do bring "infected" computers to me and although I'm very careful i guess it is possible that i've caught a virus.

Whats odd is that I have only noticed these links appear on one website. You would think if it were a network infection these sort of things would appear everywhere.

Link to comment
Share on other sites

  On 3/25/2013 at 5:57 AM, NeilD said:

As unlikely as it seems the Malware was hiding on my router a reset and re-install sorted it. Still seems fishy but all is good so this topic can be closed

I've never heard of infected router.

Did you leave generic user/password for the router access? If so then someone could change DNS, but i can't see how could a malicious code inside router, embed links onto webpages (nor can i see how could malicious code be injected in router's ram in the first place).

Link to comment
Share on other sites

  • Create New...