11
PSA: If you buy directly from Flavorwest.com -- Still in Progress
submitted over 8 years ago by Tiptup300

If you aren't familiar with what's going on Check out here:

Related Links

Original Post


THIS IS IMPORTANT IF YOU BUY DIRECTLY FROM http://flavorwest.com/

Certain information has come to attention, I'm not posting all the information till the situation has fully came together, but I would advise NOBODY BUY FROM THERE FOR RIGHT NOW. vv Buy from normal vendors. vv

IF YOU DID BUY FROM THERE WITHIN AT LEAST THE PAST TWO MONTHS, PLEASE CHECK YOUR CREDIT BALANCES REGULARLY

Let me note that nothing is concrete, I'm just trying to make everyone alert JUST IN CASE.

Verified Vendors who sell Flavorwest

Heavy Note: I'm currently talking to Flavorwest staff, this is just cautionary..... But REAAAALLY FUCKIN Cautionary. If we could get someone here more familiar with Magento store malware injection, or at least networking with people to weigh in, we could get a solid grasp on it. I'm going to be posting all correspondence with FW on here along with all other large DIY communities.

Comments
Sort
6 points
 
by icarus-_-skyover 8 years ago

Lol. "I'm not posting info so I don't blowup their spot, but watch your credit card statements. Unrelated, anyone know anything about hacking websites for credit cards?"

Kinda blew up their spot there.

6 points
 
by Tiptup300over 8 years ago

I don't owe anything to FW and they aren't particularly my favorite company. And they have been moving very slowly on what is an issue that is particularly volatile, especially if they've been alerted to it before.

I just don't want to start a panic for all those people who buy concentrates directly from flavorwest...........all of those people........................

7 points
 
by icarus-_-skyover 8 years ago

I would think, especially considering you don't seem too fond of them, that it's much more important to let the public know of the danger rather than tiptoeing around the tulips.

3 points
 
by Tiptup300over 8 years ago

I'm not sure if I'm right is the thing, that's the reason I'm asking for people who are more qualified. I suppose I should just release all the information accrued though. Good call.

4 points
 
by D-Juiceover 8 years ago

> And they have been moving very slowly on what is an issue that is particularly volatile

Why doesn't that surprise me.

Thanks for the alert.

5 points
 
by Edoc_over 8 years agoProud Sidebar Reader!

Have a look here : https://www.reddit.com/r/DIY_eJuice/comments/58n9px/debit_card_used_for_supplies_compromised_twice/

It has been mentionned about debit card

2 points
 
by Tiptup300over 8 years ago

Yeah plenty of evidence, just gotta wait till tomorrow. Gonna stick to my word.

5 points
 
by cloudCRAFT3RSover 8 years ago

Wizardlabs.com also carries fw just ordered today .

2 points
 
by Tiptup300over 8 years ago

They aren't a verified vendor. I don't know why. I originally was just gonna throw NicRiver, Bull City Vapor, & ECX up there because they're the only ones I use, but I figured I'd use the official list.

Of course normally I could say shit about ECX, but I decided to hold back this time................yeah......I will.

4 points
 
by cloudCRAFT3RSover 8 years ago

Wow thought they would be verified

3 points
 
by Tiptup300over 8 years ago

If you feel like they should be, look at what needs to be done to get them verified, see if they can be verified, and get it done man!

Community!

2 points
 
by Tiptup300over 8 years ago

List of Verified Vendors: LINK

Getting Added to The Verified Vendors List:LINK

Looks like you would need to contact them directly:

Link to Contact Wizard Labs: LINK

Asking them to email diyejuicemods@gmail.com , with all that information. Then work with them if they would be interested.

I beleib in you dude!

You were at the top of Monthly Recipe thread? That's quite an accomplishment....I must say. ;) ;) ;;)

4 points
 
by kindgroundover 8 years ago

Usually with PHP based malware injection they install a backdoor using a vulnerability in a content editor or other component/plugin that is used to upload files. It can be something as simple as a calendar that also allows you to attach/upload content images.

I'm very familiar with this regarding both WordPress and Joomla specifically but not Magento.

3 points
 
by Tiptup300over 8 years ago

According to /u/Philosaphucker 's post

There is a blog post (Which I'm not certain if it's a trustworthy source) http://gwillem.gitlab.io/2016/10/11/5900-online-stores-found-skimming/

Describes that theres a exploit in Magento software that lets malware be placed in the template data on store websites. Flavorwest is on the list of websites that are hacked.

List here: (I can't personally confirm this list either) https://gitlab.com/gwillem/public-snippets/snippets/28813

Then from the same blog (of which I can't confirm the accuracy of) it lists a website that will check a website's Magento implementation for various exploits software updates and other things.

MageReport.com, made by the same guy who did the blog post (I believe) (I can't confirm if this website is accurate) is showing that it's hacked.

I presented this information to FW through email and they said that their web developer is looking into it.

AGAIN, NOTHING IS CONFIRMED, BECAUSE THIS IS NOT MY PROFESSION AND THIS IS ALL POTENTIALLY WRONG INFORMATION

If we get someone who is an expert in the field to weigh in on it, that would be fucking sweet. I'll jump on over to every diy forum all over the place spreading the message.....on Friday. I told them I wouldn't announce anything on a big scale till Friday.

3 points
 
by h1p1n3over 8 years ago

I've been a customer there for about 3 years. My card has been compromised about 5 times. Was always wondering if it was them but had no proof. Finally, I had to use a specific card just for flavorwest ONLY so I have proof that it's them. Just waiting for it to happen again at this point.

3 points
 
by Tiptup300over 8 years ago

Please alert them through their customer service, they need to know this is a real problem.

2 points
 
by h1p1n3over 8 years ago

And what are they going to say? "Oh thanks for letting us know we'll look it over and investigate" and they'll forward the information on deaf ears. Buck gets passed and then nothing happens. This isn't Comcast or Amazon. They are a "small" business and will keep a lid on it until it really is a significant problem because this is not easy at all to resolve. Hopefully, I'm wrong.

2 points
 
by Tiptup300over 8 years ago

It's not easy to fix what already happened. But getting the malware removed isn't so tough. Or at least identifying that it is there.

3 points
 
by KingGorgover 8 years ago

FWIW https://www.magereport.com/scan/?s=http://flavorwest.com/

2 points
 
by Tiptup300over 8 years ago

Are you more familiar with that site, although the site seems super legit, reading the blog it seems it's just made by that one guy. So it's all coming from just one source, not actively pushed by Magento. Perhaps I should email Magento for comment.

2 points
 
by drumbtrover 8 years ago

The only time my CC was ever compromised was after I ordered from ECX to get that sweet sweet Yellow Cake. I hadn't used my card anywhere else that I could think of it getting compromised, besides maybe RTS Vapes. Hasn't happened since either.

1 points
 
by Tiptup300over 8 years ago

One of the many reasons I love to shovel shit onto ECX and wish they sold JF elsewhere.

Site copyright © 2025 DIY Compendium. Data courtesy of Reddit.