Unfortunately today we were the victim of a malicious social engineering attack which has resulted in our server being accessed, and our database being compromised.
To clarify, this was no hack of the WHMCS software itself, nor a hack of our server. It was through social engineering that the login details were obtained.
As a result of this, we recommend that everybody change any passwords that they have ever used for our client area, or provided via support ticket to us, immediately.
Regrettably as this was our billing system database, if you pay us by credit card (excluding PayPal) then your card details may also be at risk.
This is just a very brief email to alert you of the situation, as we are currently working very hard to ensure everything is back online & functioning correctly, and I will be writing to you again shortly.
We would like to offer our sincere apologies for any inconvenience caused. We appreciate your support, now more than ever in this challenging time.
It's fun seeing how many hosts/people on this forum have had takedown notices sent to them from WHMCS over the years for trying to use nulled versions. I won't name any names, but keep that in mind next time any of you think you're badass, because there's a lot of you.
@subigo said: It's fun seeing how many hosts/people on this forum have had takedown notices sent to them from WHMCS over the years for trying to use nulled versions. I won't name any names, but keep that in mind next time any of you think you're badass, because there's a lot of you.
HAHAHAHA that is right. You can now see who has used nulled WHMCS in the past. In the database is there a table of nulled hosts?
@subigo said: Right, I did the math and that was the low estimate. They're most likely making something in the range of $700k/month.
A close friend/source of mine actually restored the db on localhost and shown me the following:
This Month: $240,640.43 USD This Year: $1,660,666.28 USD
And he told me that WHMCS made nearly $10,000 the day they got hacked.
ChicagoVPS.net - OpenVZ/Xen Based VPS's / SolusVM Control Panel / Great Support! / 4 Geographically Diverse Locations: Los Angeles, Chicago, Buffalo, and Atlanta (NEW)!
He also did tell me there were 15-20 staff member accounts, so you have to remember Matt had quite a few employees he had to pay as well.
But from the info my source has given me WHMCS seems like a very profitable business, why they did not hire a dedicated abuse/security team is beyond me.
ChicagoVPS.net - OpenVZ/Xen Based VPS's / SolusVM Control Panel / Great Support! / 4 Geographically Diverse Locations: Los Angeles, Chicago, Buffalo, and Atlanta (NEW)!
WHMCS Not Fully hacked - Someone tried too.. But they restored it.. FAST.
---------------- WHMCS Send Mail to Us--------------------------
Unfortunately today we were the victim of a malicious social engineering attack which has resulted in our server being accessed, and our database being compromised.
To clarify, this was no hack of the WHMCS software itself, nor a hack of our server. It was through social engineering that the login details were obtained.
As a result of this, we recommend that everybody change any passwords that they have ever used for our client area, or provided via support ticket to us, immediately.
Regrettably as this was our billing system database, if you pay us by credit card (excluding PayPal) then your card details may also be at risk.
This is just a very brief email to alert you of the situation, as we are currently working very hard to ensure everything is back online & functioning correctly, and I will be writing to you again shortly.
We would like to offer our sincere apologies for any inconvenience caused. We appreciate your support, now more than ever in this challenging time.
WHMCS Limited
www.whmcs.com
But this is fascinating !!! God Bless America there is a site name HostGator - That's why we saved. No Credit Card details of ours not in Risk. :)
IWEBHOSTU.COM Bulletproof Hosting/VPS/Servers Worldwide Since 2010
@iwebhostu said: But this is fascinating !!! God Bless America there is a site name HostGator - That's why we saved. No Credit Card details of ours not in Risk. :)
Wrong, client's WHMCS installs are not affected, but those who paid whmcs.com directly with there CC are indeed affected. There CC details are all over the internet now in a simple database download.
People on WHT have already claimed to decoded it and get the full CC details already.
IF you paid WHMCS.com directly with CC destroy it immediately and get it replaced!
ChicagoVPS.net - OpenVZ/Xen Based VPS's / SolusVM Control Panel / Great Support! / 4 Geographically Diverse Locations: Los Angeles, Chicago, Buffalo, and Atlanta (NEW)!
@iwebhostu said: But this is fascinating !!! God Bless America there is a site name HostGator - That's why we saved. No Credit Card details of ours not in Risk. :)
I read somewhere on WHT that someone had access to Matt's email to get the authentication info for HostGator...
So isn't this Matt's fault to begin with for not having cphulk and having insecure webmail password?
ChicagoVPS.net - OpenVZ/Xen Based VPS's / SolusVM Control Panel / Great Support! / 4 Geographically Diverse Locations: Los Angeles, Chicago, Buffalo, and Atlanta (NEW)!
@FTN_Kevin said: client's WHMCS installs are not affected, but those who paid whmcs.com directly with there CC are indeed affected. There CC details are all over the internet now in a simple database download.
People on WHT have already claimed to decoded it and get the full CC details already.
IF you paid WHMCS.com directly with CC destroy it immediately and get it replaced!
I said the same thing.. guess people who use Hostgator servers for WHMCS Billing are perfectly ok.. LOL! Thinking about HostGator... Is they pay WHMCS by CC?
IWEBHOSTU.COM Bulletproof Hosting/VPS/Servers Worldwide Since 2010
@iwebhostu said: Thinking about HostGator... Is they pay WHMCS by CC?
For WHMCS paying HG, according to Subdigo's post here of the chat transcript they paid via CC, not sure about HG > WHMCS though: http://www.lowendtalk.com/discussion/comment/66372#Comment_66372
ChicagoVPS.net - OpenVZ/Xen Based VPS's / SolusVM Control Panel / Great Support! / 4 Geographically Diverse Locations: Los Angeles, Chicago, Buffalo, and Atlanta (NEW)!
Comments
I just received the email.
Chris :: Pioneer Network Solutions, LLC. - AllianceVPS - http://www.alliancevps.com
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksIt's fun seeing how many hosts/people on this forum have had takedown notices sent to them from WHMCS over the years for trying to use nulled versions. I won't name any names, but keep that in mind next time any of you think you're badass, because there's a lot of you.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI have not gotten any email yet, but I've seen one email that says CC details have been leaked and another that does not mention it.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI just got the email about five minutes ago.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksHAHAHAHA that is right. You can now see who has used nulled WHMCS in the past. In the database is there a table of nulled hosts?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksThere are a few different places to find the information, but "mod_takedownnotices" is the easiest place to look.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksThey've really messed up. He's making $500k and using hostgator, wtf?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI thought the same thing, why use HostGator?
Daniel.
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks@liam well, he has to host it somewhere after all.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksObviously, but companies like liquidweb are more respected ;)
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI'm sure they're making over 500k that was just an estimate based on if everyone was leasing this for 8 dollars a month.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksRight, I did the math and that was the low estimate. They're most likely making something in the range of $700k/month.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksAnyway, screw WHMCS. I am watching SpaceX's launch attempt now - should happen after 4 minutes. Let's hope they get it right this time :)
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksSo, did the database of WHMCS make it online?
My latest community project LowEndScripts.com - Listing of Debian and CentOS (RHEL) shell scripts
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksA close friend/source of mine actually restored the db on localhost and shown me the following:
This Month: $240,640.43 USD This Year: $1,660,666.28 USD
And he told me that WHMCS made nearly $10,000 the day they got hacked.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksPretty much WHMCS's entire cPanel account made it online.
Daniel.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksYour a company with a revenue of over $1,000,000 and you use shared hosting?
Daniel.
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks@Daniel i think it was their own dedi, not a shared hosting account.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksStill a lot!
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksAh right, but still use HostGator?
I just looked at the WHMCS News Feed, ouch. http://dl.dropbox.com/u/2734617/Screenshots/k0ys2_mzkhxk.png
Daniel.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI have no experience with HostGator, can't comment. At least they didn't use GoDaddy :)
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksIt is, considering its only been 5 months of the year.
Daniel.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksHe also did tell me there were 15-20 staff member accounts, so you have to remember Matt had quite a few employees he had to pay as well.
But from the info my source has given me WHMCS seems like a very profitable business, why they did not hire a dedicated abuse/security team is beyond me.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWHMCS Not Fully hacked - Someone tried too.. But they restored it.. FAST.
---------------- WHMCS Send Mail to Us-------------------------- Unfortunately today we were the victim of a malicious social engineering attack which has resulted in our server being accessed, and our database being compromised.
To clarify, this was no hack of the WHMCS software itself, nor a hack of our server. It was through social engineering that the login details were obtained.
As a result of this, we recommend that everybody change any passwords that they have ever used for our client area, or provided via support ticket to us, immediately. Regrettably as this was our billing system database, if you pay us by credit card (excluding PayPal) then your card details may also be at risk.
This is just a very brief email to alert you of the situation, as we are currently working very hard to ensure everything is back online & functioning correctly, and I will be writing to you again shortly.
We would like to offer our sincere apologies for any inconvenience caused. We appreciate your support, now more than ever in this challenging time.
WHMCS Limited
www.whmcs.com
But this is fascinating !!! God Bless America there is a site name HostGator - That's why we saved. No Credit Card details of ours not in Risk. :)
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWrong, client's WHMCS installs are not affected, but those who paid whmcs.com directly with there CC are indeed affected. There CC details are all over the internet now in a simple database download.
People on WHT have already claimed to decoded it and get the full CC details already.
IF you paid WHMCS.com directly with CC destroy it immediately and get it replaced!
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksAll this is HostGators fault.
Daniel.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI read somewhere on WHT that someone had access to Matt's email to get the authentication info for HostGator...
So isn't this Matt's fault to begin with for not having cphulk and having insecure webmail password?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI heard somewhere that they pretended to be Matt, and then HostGator gave them the password, and Matt used it on other sites (including his gmail)
So I guess its partly HostGators fault and WHMCSs for using HostGator and using same password everywhere.
Daniel.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI said the same thing.. guess people who use Hostgator servers for WHMCS Billing are perfectly ok.. LOL! Thinking about HostGator... Is they pay WHMCS by CC?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksFor WHMCS paying HG, according to Subdigo's post here of the chat transcript they paid via CC, not sure about HG > WHMCS though: http://www.lowendtalk.com/discussion/comment/66372#Comment_66372
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks