Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


WHMCS Hacked - Page 11
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

WHMCS Hacked

18911131424

Comments

  • rds100rds100 Member

    @HC_Ro ah, that one, thanks. But I think the exploit didn't work if you followed the "extra security steps" recommended by whmcs and moved your templates_c, attachments and downloads folder, as suggested in the documentation? http://docs.whmcs.com/Further_Security_Steps

    And also whmcs was quite quick to release a fix and announcement about this. So i don't blame them for that one - every software has bugs, they did the right thing in the situation.

  • DanielMDanielM Member

    it would appear the db has been released
    https://twitter.com/#!/joshthegod

  • AsimAsim Member

    @DanielM said: it would appear the db has been released
    https://twitter.com/#!/joshthegod

    Yes, @Daniel pointed out the same.
    P.S. I have already downloaded the data and saw the horrible info it has

  • @DanielM said: it would appear the db has been released

    https://twitter.com/#!/joshthegod

    Your a few hours late :P

  • DanielMDanielM Member

    @Daniel said: Your a few hours late :P

    Been busy today.

    @Asim

    just noticed lol, what kind of info? PII?

  • AsimAsim Member

    @DanielM said: just noticed lol, what kind of info? PII?

    yes, names, emails, address, phone, encrypted (which can be decrypted) CC numbers and such. Even ticket history, replies, emails log and what not

    This was just info but when you see that in the dump and posted online, it becomes horrible info

  • DanielMDanielM Member

    @Asim said: yes, names, emails, address, phone, encrypted (which can be decrypted) CC numbers and such. Even ticket history, replies, emails log and what not

    ouch,

  • qhosterqhoster Member

    Yes all is backed up and uploaded. A lot of work for WHMCS to clean their image now.

  • AsimAsim Member

    Just another quick update as I know there's a lot of rumours and speculation going around. Right now to compound matters, we are experiencing a large scale DDOS attack, which started at around 1am last night, and continues to this moment, so accessing the site may be intermittent for the time being due to the protection hardware that has been put in place for that. We know we've let you down. Although the attack yesterday was not directly due to any lapses in the security in place on either our server or WHMCS itself, we realise that we could, and should, have had a more robust hosting infrastructure in place. Plans have already been put in motion for a new multi-server hosting infrastructure to be setup and migrated to. As soon as we get things sorted, we'll be back online and give you another update. In the meantime, thank you for bearing with...

    http://blog.whmcs.com/?t=47672

  • gianggiang Veteran

    @Jack said: Moving to BuyVM ? lol

    You should give them this advise, you may got a chance to get a lifetime WHMCS license ;)

  • HC_RoHC_Ro Member
    edited May 2012

    Per some folks on WHT

    Seems they found Josh

    http://pastebin.com/KrRG81e4

    uh oh! http://i46.tinypic.com/28lgmf.jpg

    he should be banned from the internet just on the basis of using a dollar store headset

    Thanked by 1DimeCadmium
  • So why did they list the hfu.cc IPs? Just ebcause they hosted their files with them? o0

  • @HC_Ro said: Seems they found Josh

    http://pastebin.com/KrRG81e4

    How that is written reminds of how Aldryic writes :P. Not accusing anybody of anything, of course.

  • markmark Member

    How about we take this opportunity to see if something useful can come from this - such as searching the database for UptimeVPS and seeing if there's any genuine contact details for them?

  • AldryicAldryic Member

    @GetKVM-Ash said: How that is written reminds of how Aldryic writes :P

    I know the difference between "your" and "you're" :P

    (That, and I prefer housecalls to pastebin threats :3)

    Thanked by 1MrDOS
  • UgNazi website is down :p

  • markmark Member

    @Jack There's quite a lot of information at trackingdownuptimevps.org

  • markmark Member

    No surprise it's closed, but the address details might be interesting - completely different area of the country to where it was believed he was.

  • I thought all details of UptimeVPS were found out already looong ago? The stuff at trackingdownuptimevps.org seems pretty conclusive.

  • markmark Member

    @gsrdgrdghd said: I thought all details of UptimeVPS were found out already looong ago? The stuff at trackingdownuptimevps.org seems pretty conclusive.

    Never hurts to get more - this address is totally different.

  • gsrdgrdghdgsrdgrdghd Member
    edited May 2012

    @mark said: Never hurts to get more - this address is totally different.

    If you want to get more, he recieved a plaintext password in his welcome email (not implying that you should try if that password works for his email account or so!)

  • gsxgsx Member

    This might be too easy of a case for the FBI...

  • laaevlaaev Member

    @Asim said: Even ticket history, replies, emails log and what not

    Numerous people on WHT have reported tickets and services are not existing in the DB and that the hacker didn't release a full db.

  • exussumexussum Member

    oh jeez, The email table + lib_mysqludf_preg = very quick password retrieval :(

    WHMCS are gonna struggle to recover from this

  • laaevlaaev Member

    @Jack said: Ticket's and product's aren't.

    then why did you ask me to cite my source if you already know. lol

  • laaevlaaev Member

    @Jack said: I just checked when you said it after i had replied.

    Aah ok. I wonder why they didn't release a full db.

  • laaevlaaev Member

    Wow I am only 20 miles away from this hacker according to his address in that Pastebin.

  • laaevlaaev Member

    Look here for more info about Josh: http://whmcs-hacker.soup.io/

  • laaevlaaev Member

    @Jack said: Those domains are like $130 what a waste!

    Looks like he will have fun with @HostBluff inmates in prison.

Sign In or Register to comment.