Page 1 of 1

Re: Prestashop - Malware threat

Posted: 08 Jan 2020, 11:26
by mrs maggot
For those that use prestashop....
[TABLE="width: 100%]
[TR]
[TD="class: m_1863324591166799735qt-es-m-txt-c, align: left][FONT=&quot]Dear PrestaShop user,[/FONT]

[FONT=&quot] [/FONT]

[FONT=&quot]On January 2nd, we discovered a malware named XsamXadoo Bot. This malware can be used to have access to an online store and take control of it.[/FONT]

[FONT=&quot] [/FONT]

[FONT=&quot]We now believe that the bot used a known vulnerability of the PHP tool PHPUnit that has been reported as CVE-2017-9841.[/FONT]

[FONT=&quot] [/FONT]

[FONT=&quot]Here is what you need to do, it should take only 5 minutes.[/FONT]

[/TD]
[/TR]
[TR]
[TD="class: m_1863324591166799735qt-es-m-txt-l, align: left][h=2]https://www.prestashop.com/en/security- ... dQLTHAORkQ[/h]

If there is anyone who understands all of this and can help me check my site please let me know. [/TD]
[/TR]
[/TABLE]

Re: Prestashop - Malware threat

Posted: 08 Jan 2020, 12:04
by webtrekker
Here's a more detailed explanation ... https://build.prestashop.com/news/criti ... 1578484312

Basically, if your Prestashop directories contain any folder marked 'phpunit' then simply delete the named folder(s). If your site has already been compromised then you will have to seek professional advice. If no folders named 'phpunit' are discovered then your site is safe.

Re: Prestashop - Malware threat

Posted: 08 Jan 2020, 13:54
by mrs maggot
see I am not technically savvy in any way, so I cannot see how to see the files in my shop in the first place. Hopefully someone is going to look via my hosting site today.