Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


WHMCS Security Update
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

WHMCS Security Update

SpencerSpencer Member
edited May 2012 in General

There is a WHMCS security update:
http://forum.whmcs.com/showthread.php?47828-Security-Patch

Do it fast before the scanners get ya.

«1

Comments

  • Thank you :D

  • rds100rds100 Member

    How sure are we that it is Matt who has posted this and uploaded the patch? ;-)

  • SpencerSpencer Member
    edited May 2012

    @rds100 said: How sure are we that it is Matt who has posted this and uploaded the patch? ;-)

    It was on their twitter, which he had control over. And its in the same writing method as his other posts.

    But I see what you are saying.

  • rds100rds100 Member

    He should consider PGP signing his posts / patches / software from now on. And keep his PGP keys in a safe place of course.

  • FRCoreyFRCorey Member

    You would think they would do this as a point release so people would see there's an update in the WHMCS itself. Thanks for posting.

  • SpencerSpencer Member

    @FRCorey said: You would think they would do this as a point release so people would see there's an update in the WHMCS itself. Thanks for posting.

    No problem. He is e-mailing them out too, but that could take forever. And I would hate for anybody to get their DB hacked because well that would suck.

  • qenoxqenox Member

    Just had it confirmed by Matt; it's legit and takes care of a blind SQL exploit disclosed earlier yesterday.

  • qpsqps Member, Host Rep

    I also received verification from a support ticket I opened that the patch is legit.

  • You know what this means..

    WHMCS was hacked again.

  • WilliamWilliam Member

    @Daniel said: WHMCS was hacked again.

    Well.... no comment

  • sshVMsshVM Member

    http://www.greensql.net/

    GreenSQL is an Open Source database firewall used to protect databases from SQL injection attacks. GreenSQL works as a proxy and has built in support for MySQL and PostgreSQL.

    Any review/suggestion about this?

  • SpencerSpencer Member
    edited May 2012

    @sshVM said: http://www.greensql.net/

    GreenSQL is an Open Source database firewall used to protect databases from SQL injection attacks. GreenSQL works as a proxy and has built in support for MySQL and PostgreSQL.

    Any review/suggestion about this?

    Hmm I might give that a try on my test WHMCS and see how it goes. That is an interesting idea.

    Edit
    I think it is an abandoned project.

  • V7HostV7Host Member

    Is there website down for anyone else? Can't seem to load their forum or website.

  • HC_RoHC_Ro Member
    edited May 2012

    Their site is down. I am unable to get the patch.

    Anyone know if its for 4x or just 5x?

    edit* I guess per WHT some are having errors and license validation issues with it, but prob cause they are offline, Perhaps a well timed DDOS on a immediate patch being pushed out.

    Guess I will wait =\

  • AlexBarakovAlexBarakov Patron Provider, Veteran

    @HC_Ro said: Their site is down. I am unable to get the patch.

    Anyone know if its for 4x or just 5x?

    It's for both.. I am trying to get it as well. I guess someone desided to ddos them, while playing with the sqli.

  • FRCoreyFRCorey Member

    Could open a ticket with WHMCS and ask them what's the longest variable for a post within WHMCS and update suhosin to reject anything that long. Usually that's how most attacks work by overflowing a buffer or large post length.

  • MrDOSMrDOS Member

    On a semi-related note, the site needs updating.

  • PhilNDPhilND Member

    Site is down.. god, better start pulling whmcs down!

  • jarjar Patron Provider, Top Host, Veteran

    This movie just doesn't want to end.

  • HC_RoHC_Ro Member
    edited May 2012

    Their site is up but very slow in case anyone needs to grab the patch

    http://forum.whmcs.com/showthread.php?47828-Security-Patch&p=224696#post224696

    edit* it looks like Matt is re-uploading patches to the patch as mine did not match one of the mirrors I looked at: http://www.webhostingtalk.com/showpost.php?p=8154000&postcount=88

    May want to go re-download it if you went in early.

  • onepoundonepound Member
    edited May 2012

    is a mirror of patch on WHT http://www.webhostingtalk.com/showpost.php?p=8153735&postcount=19

    this is for v1 of the patch,

  • Would appear the patch has been updated to correct MySQL connection errors, just re-applied the patch and fixes errors I was seeing to.

    Full story on WHT http://www.webhostingtalk.com/showthread.php?t=1159268

  • vedranvedran Veteran

    They patched the patch?

  • vldvld Member

    Another patch to patch the patch the patch to patch will come, shortly. Trust me.

  • KuJoeKuJoe Member, Host Rep

    @vld said: Another patch to patch the patch the patch to patch will come, shortly. Trust me.

    Isn't that what development is all about? :P

  • @vedran said: They patched the patch?

    No official word from Matt that I can find, the file sizes are different and the 2nd one I've downloaded fixes the MySQL errors

  • rds100rds100 Member

    I understand that all software has bugs but this is getting stupid now. dbconnect.php was patched in mid October 2011. And today - twice? Open the f*in software, Matt, remove the ioncube encoding, we want to do our own auditing. Why wasn't the file thoroughly reviewed the last time in the first place...

  • KuJoeKuJoe Member, Host Rep

    @rds100 said: Why wasn't the file thoroughly reviewed the last time in the first place...

    Have you ever audited your own code? There's a reason why it's not allowed in most environments. It's like an author editing their own book, it's pointless.

  • KuJoeKuJoe Member, Host Rep
    edited May 2012

    I also find it funny how everybody was pissed that they were hacked and their WHMCS was vulnerable, now they release patches to fix security exploits and people are pissed at the patches. Use another script if you don't like WHMCS but don't attack them for doing their jobs.

  • @KuJoe 100% agreed.

Sign In or Register to comment.