Was my account hacked?

Hello Cloudflare Community,

I’m having a problem with my site that, so far, has been impossible to diagnose and fix. The site is https://travelersfreeclassifieds.com and another support tech, from PayPall, just sent me code taken from my site, as he views it, which is not at all similar to the code I uploaded to the hosting servers.

The PayPall payment button is inactive in Live mode, but worked perfectly in Sandbox mode. The tech sent me a screenshot (see attachment) that has an Iframe and other code that is not apart of my site. He stated that this code, the Iframe, is what is preventing the button from being active. To make things worse, there are no error messages being generated.

The strangest thing about this situation is that when I go to the cart page and view the source code, the code is exactly what I uploaded to the hosting server. And when I search all my files on the hosting server, the “<iframe name=…” and “data-gr-ext-installed…>” and “<gramarly-desktop-integration…>” code do not exist anywhere in the files.

It occurred to me that this may be injected at some point beyond the hosting server and before the client machine that made the page requests, so somewhere or some platform outside of the normal scope of web development. This is the first time I’ve employed a CDN as a security layer and I’m not very familiar with the application or stack of applications used by Cloudflare. I would like to be able to view my site pages as cached to see if the malicious code is within the files. How do I go about doing this? Also, is it possible for someone to hack my Cloudflare account? Thank you in advance for your assistance on this issue.

Sincerely,

Rick E

That looks like a browser extension. Try disabling Gramarly and try again.

4 Likes

Hello Michael,
Thanks for your reply! I don’t have Grammarly installed in any browser. I do not have & have never downloaded Grammarly on any device. Using Spotlight (Mac) and looking through my Applications folder doesn’t turn up anything. If this is Grammarly, do you have any idea how it’s ending up in the code others see visiting my site - but not me when I download the same pages? Thanks again for your assistance!
Cheers,
Rick E

I just read your post again. The engineer you are talking to has it installed!

1 Like

Hello Michael,
I’m sorry, I don’t understand. Do you mean that the P.P. Tech has it installed on his computer? That would explain why I don’t see it when I go to the same cart pages on my website. Thanks - sorry this is getting dragged out!
Cheers,
Rick E

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.