VirtueMart Forum

VirtueMart 2 + 3 + 4 => Administration & Configuration => Topic started by: supermac on April 02, 2012, 11:01:06 AM

Title: WOAH phantom order!
Post by: supermac on April 02, 2012, 11:01:06 AM
I'm really frightned.
Yesterday I received the VM confirmation email that an order has been stored in shop with order number, customer details, ordered product etc..., I've seen the payment in my paypal account, all seems right
       BUT
in VM BE pages there isn't any order with the number indicated in email, there isn't any order with the same price amount, I can find the customer between clients but it's as he never did any order!!!!!

Today I'm still receiving orders/payments, all seems to work ....

What's happened?

(VM202 J173)
Title: Re: WOAH phantom order!
Post by: jenkinhill on April 02, 2012, 12:40:49 PM
Joomla 1.7.3 is known to be insecure and has been hacked, eg see http://forum.joomla.org/viewtopic.php?f=621&t=706027

Suggest you update ASAP and check in case your site has been attacked, but it does sound strange...
Title: Re: WOAH phantom order!
Post by: supermac on April 03, 2012, 10:39:33 AM
Thx Jenkin I don't think my site has been attacked, it seems a "hole" in the payment process on the road from order in VM and the payment on Paypal site...
The "only" one wrong thing is that the order hasn't been stored on db but the rest of the process has been completed perfectly, included the mails...
Today all is working well, but it hasn't been a nice event...
I will consider the Joomla upgrade however