Hi,

If you were replying to me I'm afraid it's not that. I've tried various permutations of the callback URL and I've now put it back to what it should be (and which was working for 9 months):
http://<wpdisplay item="MC_callback">

From scanning various pages on the topic it seems that various PHP settings, particularly to do with sessions, might affect the 302 error. It seems to me that when Worldpay issues the callback (which it does, and with the correct callback pw) Zen Cart has forgotten who it's talking about and therefore redirects it to the hacker response page.

I've finally had some word from our host and they've only sent me a link to the servers config page - phpinfo.php

I've looked at the section on sessions, but basically don't have a clue what most of it means.... can someone send me their PHP 5.3 info page in a PM or something so that I can compare??

I've been told I might be able to make changes via a php.ini file - does anyone have experience of doing that?

Thanks,
Nick