If you aren't familiar with what's going on Check out here:
Related Links
- For Reference: Debit card used for supplies compromised twice.
- PART 1/3: Heads Up, Flavor West website giving me virus warnings.
- PART 2/3: PSA: If you buy directly from Flavorwest.com -- Still in Progress
- PART 3/3: PSA: CREDIT CARD HACK: If you have bought directly from Flavorwest.com or plan to, check here now. -- (PART 3/3)
Original Post
THIS IS IMPORTANT IF YOU BUY DIRECTLY FROM http://flavorwest.com/
Certain information has come to attention, I'm not posting all the information till the situation has fully came together, but I would advise NOBODY BUY FROM THERE FOR RIGHT NOW. vv Buy from normal vendors. vv
IF YOU DID BUY FROM THERE WITHIN AT LEAST THE PAST TWO MONTHS, PLEASE CHECK YOUR CREDIT BALANCES REGULARLY
Let me note that nothing is concrete, I'm just trying to make everyone alert JUST IN CASE.
Verified Vendors who sell Flavorwest
Heavy Note: I'm currently talking to Flavorwest staff, this is just cautionary..... But REAAAALLY FUCKIN Cautionary. If we could get someone here more familiar with Magento store malware injection, or at least networking with people to weigh in, we could get a solid grasp on it. I'm going to be posting all correspondence with FW on here along with all other large DIY communities.
Lol. "I'm not posting info so I don't blowup their spot, but watch your credit card statements. Unrelated, anyone know anything about hacking websites for credit cards?"
Kinda blew up their spot there.
I don't owe anything to FW and they aren't particularly my favorite company. And they have been moving very slowly on what is an issue that is particularly volatile, especially if they've been alerted to it before.
I just don't want to start a panic for all those people who buy concentrates directly from flavorwest...........all of those people........................
I would think, especially considering you don't seem too fond of them, that it's much more important to let the public know of the danger rather than tiptoeing around the tulips.
Have a look here : https://www.reddit.com/r/DIY_eJuice/comments/58n9px/debit_card_used_for_supplies_compromised_twice/
It has been mentionned about debit card
Wizardlabs.com also carries fw just ordered today .
They aren't a verified vendor. I don't know why. I originally was just gonna throw NicRiver, Bull City Vapor, & ECX up there because they're the only ones I use, but I figured I'd use the official list.
Of course normally I could say shit about ECX, but I decided to hold back this time................yeah......I will.
Wow thought they would be verified
List of Verified Vendors: LINK
Getting Added to The Verified Vendors List:LINK
Looks like you would need to contact them directly:
Link to Contact Wizard Labs: LINK
Asking them to email diyejuicemods@gmail.com , with all that information. Then work with them if they would be interested.
I beleib in you dude!
You were at the top of Monthly Recipe thread? That's quite an accomplishment....I must say. ;) ;) ;;)
Usually with PHP based malware injection they install a backdoor using a vulnerability in a content editor or other component/plugin that is used to upload files. It can be something as simple as a calendar that also allows you to attach/upload content images.
I'm very familiar with this regarding both WordPress and Joomla specifically but not Magento.
According to /u/Philosaphucker 's post
There is a blog post (Which I'm not certain if it's a trustworthy source) http://gwillem.gitlab.io/2016/10/11/5900-online-stores-found-skimming/
Describes that theres a exploit in Magento software that lets malware be placed in the template data on store websites. Flavorwest is on the list of websites that are hacked.
List here: (I can't personally confirm this list either) https://gitlab.com/gwillem/public-snippets/snippets/28813
Then from the same blog (of which I can't confirm the accuracy of) it lists a website that will check a website's Magento implementation for various exploits software updates and other things.
MageReport.com, made by the same guy who did the blog post (I believe) (I can't confirm if this website is accurate) is showing that it's hacked.
I presented this information to FW through email and they said that their web developer is looking into it.
AGAIN, NOTHING IS CONFIRMED, BECAUSE THIS IS NOT MY PROFESSION AND THIS IS ALL POTENTIALLY WRONG INFORMATION
If we get someone who is an expert in the field to weigh in on it, that would be fucking sweet. I'll jump on over to every diy forum all over the place spreading the message.....on Friday. I told them I wouldn't announce anything on a big scale till Friday.
I've been a customer there for about 3 years. My card has been compromised about 5 times. Was always wondering if it was them but had no proof. Finally, I had to use a specific card just for flavorwest ONLY so I have proof that it's them. Just waiting for it to happen again at this point.
Please alert them through their customer service, they need to know this is a real problem.
And what are they going to say? "Oh thanks for letting us know we'll look it over and investigate" and they'll forward the information on deaf ears. Buck gets passed and then nothing happens. This isn't Comcast or Amazon. They are a "small" business and will keep a lid on it until it really is a significant problem because this is not easy at all to resolve. Hopefully, I'm wrong.
FWIW https://www.magereport.com/scan/?s=http://flavorwest.com/
The only time my CC was ever compromised was after I ordered from ECX to get that sweet sweet Yellow Cake. I hadn't used my card anywhere else that I could think of it getting compromised, besides maybe RTS Vapes. Hasn't happened since either.