Results 1 to 7 of 7
  1. #1
    Join Date
    Dec 2007
    Posts
    22
    Plugin Contributions
    0

    Default Just got two $0.01 orders - but have no such products...

    Hi, I just recieved two payments via Paypal made to my shop. These orders where both from the same guy who made a payment of $0.01 - thing is I don't have any products on my site for that amount.

    Is this something to worry about? Could it be a 'hacking' attempt?

    Also I didn't receive the [NEW ORDER] e-mail that the store normally would send. And there is no record of an order in the 'orders' section in the admin panel. Though I can see the customers name and account details...

  2. #2
    Join Date
    Jun 2003
    Posts
    33,715
    Plugin Contributions
    0

    Default Re: Just got two $0.01 orders - but have no such products...

    What version of Zen Cart? Which PayPal module is installed?
    Please do not PM for support issues: a private solution doesn't benefit the community.

    Be careful with unsolicited advice via email or PM - Make sure the person you are talking to is a reliable source.

  3. #3
    Join Date
    Dec 2007
    Posts
    22
    Plugin Contributions
    0

    Default Re: Just got two $0.01 orders - but have no such products...

    Version 1.3.8a, using PayPal IPN.

  4. #4
    Join Date
    Aug 2008
    Posts
    8
    Plugin Contributions
    0

    Default Re: Just got two $0.01 orders - but have no such products...

    Quote Originally Posted by jnms View Post
    Hi, I just recieved two payments via Paypal made to my shop. These orders where both from the same guy who made a payment of $0.01 - thing is I don't have any products on my site for that amount.

    Is this something to worry about? Could it be a 'hacking' attempt?
    Hey, did you recently setup PayPal? Both PayPal & Google Checkout carry out couple of penny transactions to verify your bank account setup. I don't think you have anything to worry. You might want to confirm this with PayPal.

  5. #5
    Join Date
    Oct 2006
    Location
    Alberta, Canada
    Posts
    4,571
    Plugin Contributions
    1

    Default Re: Just got two $0.01 orders - but have no such products...

    Quote Originally Posted by jnms View Post
    Hi, I just recieved two payments via Paypal made to my shop. These orders where both from the same guy who made a payment of $0.01 - thing is I don't have any products on my site for that amount.

    Is this something to worry about? Could it be a 'hacking' attempt?

    Also I didn't receive the [NEW ORDER] e-mail that the store normally would send. And there is no record of an order in the 'orders' section in the admin panel. Though I can see the customers name and account details...
    By the sounds of it, I would say it was a hacking 'probe' to see what would happen.

    As you don't have any pricing for 0.01 cents but somebody was able to place one, they obviously knew how to get around an error page. Not sure about Google but I know PayPal uses two (2) payment deposits of different amount and more than 0.01 cents, when confirming a Bank account. Then they ask you to insert the amount they deposited to confirm your account. Could be they've change that amount though, so it's good advice to check with PayPal.


    As to seeing the Customers Name and Account details, that is a default function of Zen Cart regardless of the Order payment being successful/unsuccessful. I'm hoping that gets changed. Although it can be helpful in troubleshooting valid Orders that had a payment problem, it can be confusing as well as somewhat of a Security issue... but maybe that's just me?

  6. #6
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Just got two $0.01 orders - but have no such products...

    Might have been some sort of probe to look for vulnerabilities or test payments.
    Zen Cart won't record an order if the payment doesn't match an order for which it's waiting confirmation, so you won't end up with rogue orders in your database from that.

    I'm not sure what you're referring to about customer information though. If you're referring to the details of who paid you when looking at the transaction in PayPal, that's to be expected ... PayPal tells you who paid the amount.

    If you figure the transaction is rogue, I recommend refunding it ... that way they won't do any chargeback.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  7. #7
    Join Date
    Oct 2007
    Posts
    1
    Plugin Contributions
    0

    Default Re: Just got two $0.01 orders - but have no such products...

    Sounds like "carding", the practice of trying out stolen credit cards to see if they are still valid.

 

 

Similar Threads

  1. Two sites but only have one Security Certificate
    By tcarden in forum Addon Payment Modules
    Replies: 2
    Last Post: 12 Aug 2013, 10:02 PM
  2. Replies: 1
    Last Post: 28 Jan 2013, 10:43 PM
  3. Just installed Spanish but got Fatal errors
    By Dashizna in forum Addon Language Packs
    Replies: 1
    Last Post: 4 Oct 2006, 12:17 AM
  4. Just upgraded to 1.3.5, ok but two glitch
    By camay123 in forum Upgrading from 1.3.x to 1.3.9
    Replies: 4
    Last Post: 7 Sep 2006, 01:34 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR