v1.7x-v8x-v9x One Page Checkout & Social Login – PayPal, Stripe, COD v.2.9.4

vivozivo

Well-known member
Master
Diamond
Elite
Joined
Sep 24, 2019
Messages
1,521
Reaction score
986
Points
113
NullCash
1,159
1762516357796.png
One Page Checkout & Social Login simplifies the checkout process, enabling customers to check out faster, more easily, and securely. It supports PayPal, Stripe, PrestaShop Checkout, Google Pay, Amazon Pay, COD, bank wire, etc.

LINK

Test it and if you are satisfied, purchase from developer.
It is a matter of shop security.
 

Attachments

  • v2.9.4-ets_onepagecheckout.zip
    655.8 KB · Views: 29
  • readme_en.pdf
    2 MB · Views: 15

yog78

Active member
XNullUser
Joined
May 25, 2021
Messages
1,422
Reaction score
8
Points
38
NullCash
3,965
Thank you very much for sharing this module.
 

JDforce7

Well-known member
Diamond
Elite
XNullUser
Joined
Apr 14, 2024
Messages
409
Reaction score
456
Points
63
Location
Pandora
NullCash
2,489
Thank you very much for sharing this module.
 

hxcode

Well-known member
Master
Diamond
Elite
Joined
Aug 16, 2020
Messages
3,902
Reaction score
465
Points
83
NullCash
8
Thank you very much for sharing this module.
 

freiserk

Well-known member
☆☆ Special ☆☆
☆ Pro ☆
Master
Joined
Jan 24, 2019
Messages
3,535
Reaction score
6,635
Points
113
NullCash
29,152
The file
"ets_onepagecheckout/views/templates/hook/frontJs.tpl"
is hard coded and contain the url
https://zdrowylab.pl
It's loaded with "echo" from /ets_onepagecheckout/controllers/front/callback.php using the etsProsessProfile function.

1762701710342.png

There's also a hidden ".info" file with encryption in the module's root directory, present in both versions 2.7.4 and 2.7.5.

It's likely loaded from:

classes/OverrideUtil

classes/src/Storage/Session.php

Or even from order.php

In version 2.7.3, none of the above appears.

Nice catch!

Now let's see where they got the @vivozivo module from.
 

alphaz0r

New member
XNullUser
Joined
Nov 9, 2025
Messages
11
Reaction score
1
Points
3
Location
Lisbon
NullCash
5
Weird! even though thanks for the share! it's still useful for people who know how to code. They can still review the code and use what is there to build functionality
 

moonfire

Well-known member
Diamond
Elite
XNullUser
Joined
May 3, 2021
Messages
1,169
Reaction score
459
Points
83
NullCash
1,742
OLD VERSION.

LAST VERSION IS 2.9.5
For the record, version 2.9.5 on this forum also contain the suspicions code that @freiserk , @alphaz0r and myself point out
Post automatically merged:

It's loaded with "echo" from /ets_onepagecheckout/controllers/front/callback.php using the etsProsessProfile function.

View attachment 140454

There's also a hidden ".info" file with encryption in the module's root directory, present in both versions 2.7.4 and 2.7.5.

It's likely loaded from:

classes/OverrideUtil

classes/src/Storage/Session.php

Or even from order.php

In version 2.7.3, none of the above appears.

Nice catch!

Now let's see where they got the @vivozivo module from.
As for the hidden ".info" file, its very common in the modules on this forum these days.
I haven't figured out where they come from yet.
Post automatically merged:

Wish me luck, going to download it and audit it, then edit out the rogue code 🙏
I wish you the best of luck :)

I've modified this module a bit. Removed some stuff and added some stuff. But I'm not done yet,
Let me know if you need a second eye when removing the rogue code.
 
Last edited:

infoseek

Member
XNullUser
Joined
Aug 11, 2021
Messages
870
Reaction score
3
Points
18
NullCash
18
thanks ,but old and please check if the above problem exists?
 

freiserk

Well-known member
☆☆ Special ☆☆
☆ Pro ☆
Master
Joined
Jan 24, 2019
Messages
3,535
Reaction score
6,635
Points
113
NullCash
29,152
For the record, version 2.9.5 on this forum also contain the suspicions code that @freiserk , @alphaz0r and myself point out
Post automatically merged:


As for the hidden ".info" file, its very common in the modules on this forum these days.
I haven't figured out where they come from yet.
Post automatically merged:


I wish you the best of luck :)

I've modified this module a bit. Removed some stuff and added some stuff. But I'm not done yet,
Let me know if you need a second eye when removing the rogue code.

We need to remove that ".info" file because it's extremely suspicious, or, in an isolated local environment, see what it generates and how it behaves on a network.

Thanks for your work.
 
Top