My PrestaShop site got hacked! What should I do?

Posted on , by Lucie Fremaux

Our solutions and expert advice

Security for e-commerce sites is a major concern for site owners. Is your PrestaShop site already infected? You need to act as quickly as possible.
If you’re not sure whether you’ve been the victim of an attack, it’s essential to do everything you can to prevent one from happening.
In any case, the best protection against cybercrime is prevention.

Cybercrime numbers are on the rise:

The 2021 Fevad report states that 44% of retailers worldwide were victims of a ransomware attack the previous year. (Source: Sophos Ransomware Retail, 2021)

Another study conducted by EY also revealed that a high percentage of companies worldwide (82%) reported an increase in attacks classified as destabilizing.

(Source: Concerning findings from EY’s global survey of 1,400 information security officers (CISOs) and cybersecurity executives conducted between March and May 2021)

More generally, CMS platforms built on add-on modules (WordPress/WooCommerce, PrestaShop, Magento…) are particularly exposed to potential security flaws, due to the large number of different vendors developing these extensions. How they’re coded depends on each developer’s (vendor’s) knowledge of security best practices.

As a result, regularly assessing your PrestaShop store’s security level is essential to ensure the trust and safety of online shoppers, as well as to protect your company’s reputation and long-term viability.

To address these challenges, our team has developed a Security Pack specifically designed to help our clients ensure their PrestaShop site is protected.
In practice, to set up this Pack, we carry out an in-depth analysis of your modules and PrestaShop’s core to identify potential vulnerabilities. In the event of an infection, we investigate to assess the source and severity of the infection. We then deploy fixes to ensure the security of the site’s and its customers’ data.
To help you check and maintain your PrestaShop site’s security, here are the various steps to follow (these are the same ones we use as part of our Security Pack):

YOUR SITE IS INFECTED:
Step 1: Qualifying the attack
Step 2: Analyzing the attack
Step 3: Deploying measures

YOUR SITE IS NOT INFECTED:
Step 4: Module analysis
Step 5: Scanning modified core files
Step 6: Analyzing PrestaShop core vulnerabilities
Step 7: Scanning non-standard files / directories
Step 8: Securing your back office
Step 9: Google Search Console, sitemaps, and robots.txt

YOUR PRESTASHOP SITE IS INFECTED:

Step 1: Qualifying the attack

If you suspect a hack, it’s important to determine whether it’s actually an attack. To do this, there are several indicators to consider.
For example:

  • unusual payment methods have been used recently
  • unauthorized access has been detected in the back-office access logs
  • a message from the attacker is directly visible (a signature)

After this step, it’s recommended to take a few measures to protect the site:

  1. back up the site to avoid any loss of important data or files.
  2. put the site into maintenance mode
  3. block access to the back office to prevent any unauthorized access during the next step.

These precautions will help reduce the risk of further attacks or data loss during the process of resolving the issue.

Step 2: Analyzing the attack

An initial analysis is needed to understand the scale of the attack and assess its severity.
This analysis consists of several actions:

    • First, you should check whether there’s a visible infection or modified files. If so, the analysis will focus on an infection affecting the front office.
    • Next, a full scan of the store’s files is needed to detect known threats, which will help prepare fixes and more easily determine the entry point.
    • In addition, it’s crucial to check modified and added files by comparing dates against a backup. The changes will be assessed to determine whether they are legitimate changes or traces of an infection.
    • Finally, Apache access logs and PHP error logs should be analyzed to look for any traces of access at the times files were modified. The goal will be to isolate IP addresses or user agents that accessed webshells or modified files over HTTP. It will also be necessary to review server and FTP access as a precaution.

Step 3: Deploying measures

Once the attack has been identified and analyzed, it’s crucial to quickly deploy measures to prevent any further damage:

      • Block the attacker (for example, by blocking IP ranges).
      • Disinfect the infected files, to prevent any reinfection.
      • Remove the detected entry point(s) (for example: a vulnerable module that was exploited).
      • Restore a backup – ONLY if the source of the attack has been identified and can be fixed.
      • Change all access credentials: FTP, back office (for all employees), databases.
If you have any doubts about the nature of the infection, it’s recommended to continue the analysis until the attack is fully qualified or until all doubts have been ruled out. This may involve looking for additional evidence and seeking help from IT security experts to confirm or rule out your suspicions. It’s essential to handle security incidents with the utmost care to protect your business and your customers.

 

YOUR SITE IS NOT INFECTED (or the attack has not yet been qualified):

Step 4: Module analysis

Modules on a PrestaShop site can serve as entry points for attacks. These entry points can take the form of malicious code injection or the exploitation of SQL vulnerabilities. To ensure your site’s security, it’s important to review all installed modules and compare their versions against those known to have public vulnerabilities. Even if a module is disabled or not installed, it can still be vulnerable, so it’s essential to analyze all modules present on the server. Additional checks or an update may be needed to maintain a good level of security.

To help you carry out a thorough analysis, Profileo has developed the Zentria module. Installation is simple: just add it to your dashboard and create an account to run a scan.Once set up, Prestascan Security lists all your modules and assesses their vulnerability status or any updates needed. This lets you quickly identify modules that need particular attention and take action to strengthen your site’s security.
Download Zentria

Step 5: Scanning modified core files

This analysis checks whether any of PrestaShop’s native files have been modified. The goal is to check whether malware has infected the core files. Note that file changes may also have been made by developers. These don’t pose any particular security risk. However, it’s not advisable to modify native files directly.

Step 6: Analyzing PrestaShop core vulnerabilities

If you’re running one of the most recent versions of PrestaShop, the number of vulnerabilities present in PrestaShop’s core is reduced. In general, it’s recommended to use the most recent version of the software. However, if the version you’re using is older (1.6 or earlier), it’s all the more important to analyze PrestaShop’s core. Older versions are the ones with the most vulnerabilities.

Step 7: Scanning files / directories

It’s then essential to review all files and directories that have been added to the site, whether at the root level or not, in order to detect anything that could pose a threat. In practice, we use suspicious keywords to identify any infection or vulnerability. This process is methodical but can be very complex to carry out depending on the number of files to review. Beyond known vulnerabilities, some files may be publicly accessible, which can lead to sensitive information being leaked. It is therefore important to protect the integrity of all data. The scope of this analysis covers a wide range of potential risks.

Step 8: Securing your back office

One of the fundamental security elements of a site is back-office security. This can be checked by examining the access URL. If your dashboard’s URL is easily identifiable, such as http://www.yourdomainname.com/backoffice/, this can be spotted by malicious actors. It’s better to use secure HTTPS access and rename the back-office directory to fully customize it. For example, this could be httpS://www.yourdomainname.com/BO-admin4Qx66Nd/.

Another important aspect of back-office security concerns who has access to it. We strongly recommend regularly changing employee account passwords and using strong, unique credentials. You can generate secure passwords here: https://www.cnil.fr/fr/generer-un-mot-de-passe-solide
It’s also important to disable or delete employee accounts that are no longer in use.
A quick and effective way to secure the back office is to set up two-factor authentication (2FA).

Step 9: Google Search Console, sitemaps, and robots.txt

Checking your sitemap and robots.txt files is a common step in ensuring your website’s security. Your Google Search Console lets you carry out a more in-depth analysis at this level and detect, via the “Security issues” section, any potential security issues on your website. Google will warn you if your site has been hacked and poses a security threat to your visitors.

 

Key Profileo figures

Profileo handles the maintenance and security of PrestaShop stores.
To date, across all the Security Packs we’ve implemented*, we’ve found that:
72 % of sites are infected at the time they subscribe to the Security Pack.
48 % of infections originate from the exploitation of a module vulnerability.
55 % of infected sites are running an older version of PrestaShop (1.6 and earlier).
56 % of attacks aim to divert payment methods.

* study conducted on a sample of the last 25 PrestaShop sites managed by our teams as of 03/31/2023.

Find all our advice and news related to your PrestaShop site’s security in our dedicated article on module security vulnerability issues.

Not sure about your store’s security?

Want to make sure your modules are up to date?

Our team of PrestaShop experts handles everything. Choose the PrestaShop Security Pack or contact us directly if you’d like support on a specific security issue.

Contact us!