Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


HostSolutions hacked? - Page 14
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

HostSolutions hacked?

11214161718

Comments

  • MikaelStrangMikaelStrang Member
    edited December 2021

    @TimboJones said:

    @KermEd said:

    @TimboJones said:

    @hostingsolutionssux said:

    @Hotmarer said:
    @hostingsolutionssux If we ask nicely, will you provide us with our backups of virtual machines?

    Sorry, but I saved very few, I didn't think anyone was still using this bad host so I removed most of it.

    This guy is fucking obtuse.

    Speaking of which, you've made 9 posts in a row, and counting, with most of them to a disabled account

    You feeling OK? You know you can quote more than one person a post right?

    Consolidating unrelated quoted posts is stupid. But whining about scrolling just a little bit more is pretty lame.

    You respond to stuff but your points get invalidated as you scroll on. You should've read everything first before replying to 100 different posts, then made a big reply to everything. LET Has drafts for a reason you know :open_mouth:

    @TimboJones said: Will be very interested to know you plan on doing this. (Hint, you're a script kiddy who is full of shit). I've got some ground beef, can you make me a cow?

    Also you make zero sense here. The person already proved they hacked the website. I don't know why you're trying to make them mad when they already agreed to delete it and not do anything with it. Very annoying as my data is in there and I don't want it leaked, so pipe down. You're acting younger than whoever probably hacked it.

  • jsgjsg Member, Resident Benchmarker
    edited December 2021

    @hostingsolutionssux said:

    @default said:
    @hostingsolutionssux - what do you plan on doing with the database?

    Nothing. Although as @Jar said I also got access to the email logs sent.

    I also have all of the tickets, the passwords for all the servers (Stored in the "Encrypted" value on WHMCS, but everyone knows that can be decoded with a simple script with the value from configuration.php, which i got).

    [DB tables]

    I didn't take more because I saw zero value in the rest.

    Their "Data crash" or whatever they call it was me deleting all of the VPSes on proxmox LOL

    (emphasis mine)

    You mean the sad event when HostSolution's disks crashed? If yes then you are a criminal and should be brought to justice because your criminal actions destroyed a business and harmed thousands of innocent customers.

    As for the current hack, yes you seem to finally have made some good decisions (not abusing/publishing/selling the data) but still, outside of war hacking is despicable and criminal. But again, thanks for at least not abusing the data.

    @stevewatson301 said:
    @hostingsolutionssux how's the handover to HIBP coming up? @cociu needs it at this point, he won't learn a lesson otherwise. (It would also be kinda interesting to see how jsg reacts to the entire situation once it hits Troy's blog.)

    (a) I condemn the hacking, (b) I laud the hacker for at least not creating further harm, (c) I welcome the data being sent to HIBP, and (d) I'm not at all surprised because almost all providers have not exactly satisfying IT security and @cociu in particular had to be pretty much presumed to have little to no OpSec and protection in place.

    Plus there is a point that disturbs me quite a bit. Of course one should have different passwords (and email addresses) for different accounts, but humans being humans ...
    And the physical world data problem. On one hand one should be honest and provide true data, but otoh one obviously should not but rather provide fake data. Dilemma.

    @cociu said:
    Hello And happy Cristmas. Regards to this Topic unfortunatly is true , we are working from this morning in check how this happened and try to secure more our whmcs. For the moment seems the clients affected is the old one because the database was changed some month ago so i cannot be sure in this moment but i am feel the clients affected of this is only the clients with more than 1 year old in hostsolutions.ro.

    About my absence ... is a long story , some issue in the personal life but i hope will be better next year and i will continue only with Romanian location and change a lot in our business But will try to came with a full explications in another day . Today i have conected for this security problem not to make more drama here.

    Have a new year better !

    Edit : your payment details is verry safe , we NEVER store your payment datails all was external so no risck in this.

    IF that's even you, cociu ...

    Sorry but I don't see any reason to trust anything you say or "guarantee". But thanks for coming out of your deep cave and providing some information and such suggesting that you seem to care at least a tiny bit about your customers. May 2022 be better to all of us than 2021 was.

    @TimboJones said:
    You're the only person on LET that gets butthurt over other people thanking posts by others.

    Oh well, as usual you feel entitled to judge but didn't even get the point.

  • Thanked by 1FrankZ
  • There is nothing more entertaining, than fanatics battle each other :D and timbo gone complete bozzo. Woohoo!

    Thanked by 1AlwaysSkint
  • Got it too, I should really start using email aliases.. Any good service to recommend while we're at it?

  • @dosai said:
    He will be unbanned soon™

    Thanked by 1brejski
  • @Voigon said:
    Got it too, I should really start using email aliases.. Any good service to recommend while we're at it?

    MXroute

  • @Ganonk said:
    He will be unbanned soon™

    jsg probably already started writing BLAH BLAH BLAH message bomb to admins for unbanning his sponsor :D

    Thanked by 2Ganonk M66B
  • there is still hope for all these precious credits saved on account...

    Thanked by 1plumberg
  • FlorinMarianFlorinMarian Member, Host Rep

    @Andrews said:

    there is still hope for all these precious credits saved on account...

    Unfortunately, I'm more pessimistic, I don't think that if cociu wanted to help you, he wouldn't have done it already. :disappointed:

  • stonedstoned Member
    edited December 2021

    You must be so proud of yourself.

  • @stoned said:

    You must be so proud of yourself.

    It's Christmas, stop being such a douche to everyone.

  • @Voigon said:
    Got it too, I should really start using email aliases.. Any good service to recommend while we're at it?

    Firefox Relay⁩ or cloudflare Email Forwarding

  • Daniel15Daniel15 Veteran
    edited December 2021

    @Voigon said:
    Got it too, I should really start using email aliases.. Any good service to recommend while we're at it?

    Since everyone here has idle VPSes, you can self-host something like https://github.com/fterh/heimdall to make the VPSes actually useful.

    Personally I self-host my emails using Mailcow, and have a catchall address so I don't need to manually create aliases. I use MXRoute just for outbound relaying, but you can also use it for catchalls.

    Thanked by 1dystopia
  • @dahartigan said:

    @stoned said:

    You must be so proud of yourself.

    It's Christmas, stop being such a douche to everyone.

    You must be so proud of yourself.

  • What a drama but at least we get some info about what’s going on via this thread.

  • @stoned said:

    @dahartigan said:

    @stoned said:

    You must be so proud of yourself.

    It's Christmas, stop being such a douche to everyone.

    You must be so proud of yourself.

    The fuck is wrong with you?

  • @Voigon said:
    Got it too, I should really start using email aliases.. Any good service to recommend while we're at it?

    I use Postfix + Dovecot to host my own email server. Setup takes some effort if you're not familiar with self-hosting email but after that I barely had to touch it (just a config line here and there to make it relay emails from other VPSes).

    I've set it up such that email addressed at non-existent users are redirected to a single inbox. I use this to create multiple accounts on some websites. I guess I should use this feature more often...

    Thanked by 1stoned
  • deankdeank Member, Troll

    @dahartigan said:
    The fuck is wrong with you?

    Nothing. She is perpetually stoned.

    Thanked by 1dahartigan
  • @dahartigan said:

    @stoned said:

    @dahartigan said:

    @stoned said:

    You must be so proud of yourself.

    It's Christmas, stop being such a douche to everyone.

    You must be so proud of yourself.

    The fuck is wrong with you?

    They must've ran out of perocet dusted rocky mountain oysters.

  • t0mt0m Member
    edited December 2021

    @Demindiro said:
    I use Postfix + Dovecot to host my own email server. Setup takes some effort if you're not familiar with self-hosting email but after that I barely had to touch it (just a config line here and there to make it relay emails from other VPSes).

    Well, make sure you keep it up to date by applying security updates..

  • t0mt0m Member
    edited December 2021

    @Demindiro said:
    I've set it up such that email addressed at non-existent users are redirected to a single inbox. I use this to create multiple accounts on some websites. I guess I should use this feature more often.

    Yeah. The only downside with this catch-all approach is that you will receive spam which is sent to every single address before the ‘@‘

  • @dahartigan said:

    @stoned said:

    You must be so proud of yourself.

    It's Christmas, stop being such a douche to everyone.

    or in general

  • @stoned said:

    You must be so proud of yourself.

    1) are u tinyweasel?
    2) regardless, daddy/mommy issues?
    3) fucked up Christmas?
    4) all the above?

  • @cybertech said:

    @stoned said:

    You must be so proud of yourself.

    1) are u tinyweasel?
    2) regardless, daddy/mommy issues?
    3) fucked up Christmas?
    4) all the above?

    Thanked by 1cybertech
  • @t0m said:

    Yeah. The only downside with this catch-all approach is that you will receive spam which is sent to every single address before the ‘@‘

    That is a potential problem,I've used wildcard on my domain for a few years and not suffered from any major spam issues

    Thanked by 1t0m
  • DPDP Administrator, The Domain Guy

    @Razza said:
    @t0m said:

    Yeah. The only downside with this catch-all approach is that you will receive spam which is sent to every single address before the ‘@‘

    That is a potential problem,I've used wildcard on my domain for a few years and not suffered from any major spam issues

    Same here.

    I've had catch-all for over a decade and honestly I don't get that much spam either.

  • brueggusbrueggus Member, IPv6 Advocate

    @DP said:

    @Razza said:
    @t0m said:

    Yeah. The only downside with this catch-all approach is that you will receive spam which is sent to every single address before the ‘@‘

    That is a potential problem,I've used wildcard on my domain for a few years and not suffered from any major spam issues

    Same here.

    I've had catch-all for over a decade and honestly I don't get that much spam either.

    Me neither. If I don't want to receive emails for specific addresses, I just redirect them to a non existing mailbox so that the sender gets a delivery error.

  • how's the hangover @TimboJones

Sign In or Register to comment.