1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Oscommerce site Malware warning

Discussion in 'Security' started by Weirfire, Jan 18, 2012.

  1. #1
    One of my customers sites has been constantly bringing up Malware warnings to visitors. Sometimes the site is loading and working fine with no issues and then a random malware issue occurs and some customers have received really bad virus infections from visiting the site.

    I've scanned through all the files with nothing showing up, my hosts have scanned through all the files with nothing showing up, changed all the passwords hundreds of times, set up specific IP management for any admin pages so that only those using it can even get near it.

    Does anyone have any suggestions on what we can do to avoid these problems?


    PS Here is one of the security messages which popped up on the site;

     
    Weirfire, Jan 18, 2012 IP
  2. sparek

    sparek Peon

    Messages:
    68
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Is your site being redirected to Google's Malware page?

    If that's the case, then your website has been blacklisted by Google. You may contact them for more information on the matter.

    You mention that your website is using osCommerce. Were you keeping osCommerce up-to-date? I'm not sure if it's really possible to know what version of osCommerce you have installed and what version is the most up-to-date. They don't have a very solid versioning system.
     
    sparek, Jan 18, 2012 IP
  3. Weirfire

    Weirfire Language Translation Company

    Messages:
    6,979
    Likes Received:
    365
    Best Answers:
    0
    Trophy Points:
    280
    #3
    I've used the webmaster tool at Google and carried out a malware crawl and it showed up as having nothing problematic.

    The site is highly customised so keeping it up to date is a task in itself since any updates needs some careful manual code updates. I've informed my customer that this needs to be done at least once a year though but I've not been able to persuade them to move on this yet.

    I'd be happy to share the URL via PM if you would like to have a closer look?
     
    Weirfire, Jan 19, 2012 IP