@Daniel said: Basically, a set of rules WHMCS must comply with for big companies and governments to use it.
No. A set of rules anyone in the US must comply with to handle direct credit cards payments (as in, payments not through a payment service such as PayPal). Fines for noncompliance can be in order of hundreds of thousands of dollars per day of noncompliant operation.
@MrDOS said: Fines for noncompliance can be in order of hundreds of thousands of dollars per day of noncompliant operation.
Well since WHMCS is an UK and not an US company that shouldn't be any problem. However it was just plain stupid of them to store all CC details in "plaintext"
So wait, isn't WHMCS the guys that would rage on you if you wanted to store your CC's within your own DB because it violated xyz laws or you needed heavy PCI compliance?
Francisco
BuyVM - OpenVZ & KVM Based / TUN, PPTP, FUSE, SIT & GRE Enabled! / Stallion Control Panel
@MrDOS said: No. A set of rules anyone in the US must comply with to handle direct credit cards payments (as in, payments not through a payment service such as PayPal).
Exactly. That is why I don't run credit cards through my WHMCS and only do them through a 3rd party like WHMCS or 2co.
@MrDOS said: No. A set of rules anyone in the US must comply with to handle direct credit cards payments (as in, payments not through a payment service such as PayPal). Fines for noncompliance can be in order of hundreds of thousands of dollars per day of noncompliant operation.
@Insidiea said: Anyone else wants to add to this/confirm?
Well this depends very much on your country's legislation.
However even if its illegal to download/view it i don't think anybody who doesn't abuse the data would get in trouble for it.
This is a confirmation email that you have registered with WHMCS. Your new account has been setup and you can now login to our client area using the details below.
I have a quick question, I quickly skimmed through the 9 pages of this topic and didn't see an answer, I had a WHMCS license through LicensePal, canceled it quite awhile ago. So since I paid at LicensePal, WHMCS doesn't have my credit card details, right?
A new WHMCS exploit scanner is being passed around IRC now. It checks for exploits on every single IP listed as active in the database. It's not that bad now (unless you never update WHMCS), but this is going to make future exploits a bad thing. It's not like most people are going to change their server IP just to protect themselves.
@subigo said: A new WHMCS exploit scanner is being passed around IRC now. It checks for exploits on every single IP listed as active in the database. It's not that bad now (unless you never update WHMCS), but this is going to make future exploits a bad thing. It's not like most people are going to change their server IP just to protect themselves.
Phewww I just moved my WHMCS server today (unrelated to the hacking) Perfect day for this to happen!
@subigo said: A new WHMCS exploit scanner is being passed around IRC now.
What shady IRC networks are you on?
It's LET, you should expect unnecessary overreactions. "Gimme the sound, to see, Another world outside that’s full of All the broken things that I made"
Comments
Basically, a set of rules WHMCS must comply with for big companies and governments to use it.
Daniel.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksNo. A set of rules anyone in the US must comply with to handle direct credit cards payments (as in, payments not through a payment service such as PayPal). Fines for noncompliance can be in order of hundreds of thousands of dollars per day of noncompliant operation.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksSweet, that is cheap. Just signed up to the site, do you mean CAD? Signed up to the Canadian one.
Asad
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWell since WHMCS is an UK and not an US company that shouldn't be any problem. However it was just plain stupid of them to store all CC details in "plaintext"
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksSo wait, isn't WHMCS the guys that would rage on you if you wanted to store your CC's within your own DB because it violated xyz laws or you needed heavy PCI compliance?
Francisco
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksAFAIK it (PCI compliance) is not an US thing. It is Visa/Mastercard requirement. They are the ones who fine you.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksExactly. That is why I don't run credit cards through my WHMCS and only do them through a 3rd party like WHMCS or 2co.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI stand corrected, I thought wrong.
Daniel.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksCorrect.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksMy bad, then. I knew it was controlled by a conglomerate of credit card companies, but I thought they kept it within US borders.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksAnyone else wants to add to this/confirm?
Insidiea
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWell this depends very much on your country's legislation. However even if its illegal to download/view it i don't think anybody who doesn't abuse the data would get in trouble for it.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWell, I don't think it would hurt just to check what data of yours in there. Thats the reason I downloaded it.
Daniel.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksSo did anyone actually try to login?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI'm a client, do I need to jump in and "check" things? Or is it "just fine"? :)
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI have a quick question, I quickly skimmed through the 9 pages of this topic and didn't see an answer, I had a WHMCS license through LicensePal, canceled it quite awhile ago. So since I paid at LicensePal, WHMCS doesn't have my credit card details, right?
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksIf you tell me what to look for i can check it for you
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksCorrect. You're credit card is safe.
Asad
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks... untill they get social engineered through their hosting provider....
LiquidHost - https://liquid-solutions.biz
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksI think your meaning safe, if LicensePal was giving out CC info to WHMCS that would be worrying.
Daniel.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWho says it's stolen? It may well be "public" found somewhere, which they CAN use in an investigation.
Now pretending to be a Mexican!
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWhen will WHMCS get control of their twitter again ;(
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksSo, who's willing to hack ugnazi? :P
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksThat would be stooping to their level :p
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksNot like pulling the leaked database to look up financial figures and personal information on other people, right? -_-;
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksHahaha good point
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksA new WHMCS exploit scanner is being passed around IRC now. It checks for exploits on every single IP listed as active in the database. It's not that bad now (unless you never update WHMCS), but this is going to make future exploits a bad thing. It's not like most people are going to change their server IP just to protect themselves.
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksPhewww I just moved my WHMCS server today (unrelated to the hacking) Perfect day for this to happen!
- Spam
- Abuse
- Troll
0 • Disagree Agree ThanksWhat shady IRC networks are you on?
It's LET, you should expect unnecessary overreactions. "Gimme the sound, to see, Another world outside that’s full of All the broken things that I made"
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks. #lowendbox on irc.freenode.net
- Spam
- Abuse
- Troll
0 • Disagree Agree Thanks