Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


HostSolutions hacked? - Page 4
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

HostSolutions hacked?

1246718

Comments

  • deankdeank Member, Troll

    The timing is way too convenient.

    I will be a dick to say that this was planned.

  • found mine in spam, then came here to see, thankfully I keep everything unique per service for many years now.

    Thanked by 2ehab afn
  • Didn't get mine, I feel left out :disappointed:

    To the people that received the mail, when was your most recent login on the billing panel?

    Thanked by 1ehab
  • BogddanBogddan Member
    edited December 2021

    @jmgcaguicla said:
    Didn't get mine, I feel left out :disappointed:

    To the people that received the mail, when was your most recent login on the billing panel?

    Mine was 2021-08-05.

  • Just stopping in to say #metoo

  • niknar1900niknar1900 Member
    edited December 2021

    Every time I think I'm gonna use some of this useless credit, shit like this happens. Oh, the email was in my spam, and thank god I used paypal.... And fuck me for believing a romanian perfume store owner and his basement would make an excellent place to host anything... at all 😂 (insert emoji of me shooting my brains out)

  • Thanked by 2dahartigan JasonM
  • @jmgcaguicla said:
    Didn't get mine, I feel left out :disappointed:

    To the people that received the mail, when was your most recent login on the billing panel?

    Mine was 2019-07-15

  • Hello hackers, if I comment my oder id could you please double the backups?

  • I come here to see what will jsg say.

    I expect him to say:
    X out of Y of my servers are still online.
    That rotten horse is not dead, it's to early to draw the conclusion.
    Wall of text that express how he cares the community.

    I bet $7 on this.

  • Fortunately I didn't register there.

    Thanked by 1tux
  • fortunately, i only used fakedata and throwaway email and phone number. paranoia does make sense from time to time.

    Thanked by 2MannDude afn
  • Mr_TomMr_Tom Member, Host Rep

    Got one too. I was suspiscious at first thinking it could be "public" data from domains etc but it has my home IP listed.

    I only ever had a free VM that was won so no card details luckily but still not good.

  • @alpha110 said:
    fortunately, i only used fakedata and throwaway email and phone number. paranoia does make sense from time to time.

    Exactly, fake data and disposable email, the best combo.

  • SaahibSaahib Host Rep, Veteran

    This @cociu is never ending episode of surprises on LET. This time user privacy has been involucrated .

    Thanked by 1JasonM
  • Mr_TomMr_Tom Member, Host Rep

    @jar said: The only confirmation we have is someone saying the password hash matches their pass, right? Or did I misread?

    Can confirm password hash in email seems to match my password used at HS.

    It was a throw away pass so I just used the "decrypt" part of https://bcrypt-generator.com/ and it came up as a match.

    Thanked by 2jar Falzo
  • it is a match for me too.
    rip

  • Mr_TomMr_Tom Member, Host Rep

    The IP part was also a give away too, as it was a very specific v6 address that I only used for a short amount of time but it ties in with the "lastlogin" field.

  • typicalGtaTGtypicalGtaTG Member, Host Rep

    @dirtminer said:

    @BlazinDimes said: Bitwarden, generate a new password for EVERY SERVICE, EVEN LOCAL ONES (self-hosted)

    Next year, you'll get an email with your bitwarden passwords.
    Paper or nothing!

    I feel like if something manages to connect to my desk router and then guess my already complicated bitwarden password (prolly easier to just take the RPi lol) then I'd die of a heart attack so my passwords would kinda be useless to me at that point... :shrug:

  • jsgjsg Member, Resident Benchmarker

    @Kiwi83 said:
    I come here to see what will jsg say.

    I expect him to say:
    X out of Y of my servers are still online.
    That rotten horse is not dead, it's to early to draw the conclusion.
    Wall of text that express how he cares the community.

    I bet $7 on this.

    He will say that you are not particularly smart and provably wrong.

    Oh and regards to cybertech, the "benchmark king" at LES who of course liked your stupid and wrong comment.

  • Hacked or sold?

    Thanked by 1JasonM
  • @corbpie said:
    Hacked or sold?

    probably depends on which category you'd put "harddrives from OLX" into ;-)

    on another note, I'd be interested in the recency of that data. from what it seems so far only rather old clients confirmed in here, 2017/2018/2019.

    as the table obviously holds a "lastlogin" data I'd say it be interesting to find the most recent one amongst the people here who got such a mail. especially those with (more or less) 'active' services most likely (tried to) logged in more recently, so...

  • brueggusbrueggus Member, IPv6 Advocate

    @Falzo said:
    as the table obviously holds a "lastlogin" data I'd say it be interesting to find the most recent one amongst the people here who got such a mail. especially those with (more or less) 'active' services most likely (tried to) logged in more recently, so...

    Shows 2021-11-25 for me, so the data seems to be recent.

  • @brueggus said:

    @Falzo said:
    as the table obviously holds a "lastlogin" data I'd say it be interesting to find the most recent one amongst the people here who got such a mail. especially those with (more or less) 'active' services most likely (tried to) logged in more recently, so...

    Shows 2021-11-25 for me, so the data seems to be recent.

    wow, thanks, that was fast. also wouldn't have expected that to be honest...

  • gdarkogdarko Member
    edited December 2021

    If i am not mistaken, WHMCS uses BCRYPT so, the password hashes are useless?

  • brueggusbrueggus Member, IPv6 Advocate

    @gdarko said:
    If i am not mistaken, WHMCS uses BCRYPT so, the password hashes are useless?

    Yes, but:

    @jar said:
    Don't forget by default WHMCS sends the password you create for your login to you via email. It also sends you the password generated for services on provision typically. These are stored in plain text in the email history table.

    Thanked by 2tux default
  • @cociu the fucking guy He is apparently mouth dead and shits on everything

    Thanked by 1JasonM
  • @brueggus said:

    @gdarko said:
    If i am not mistaken, WHMCS uses BCRYPT so, the password hashes are useless?

    Yes, but:

    @jar said:
    Don't forget by default WHMCS sends the password you create for your login to you via email. It also sends you the password generated for services on provision typically. These are stored in plain text in the email history table.

    Well. F*ck WHMCS then, we should collectively sue them for storing this sensitive data in plain text.

    What is the logic of storing email contents in the database in plaintext when they advertise encryption bla bla. Fu*king idiots.

  • It's the root password you set during the order process for your VPS which is sent in clear text. It's not the account password. And most of the people know, that WHMCS does this. People who use their super secret 1337P455w0r7 there, well, can't help.

  • brueggusbrueggus Member, IPv6 Advocate

    @zappata said: It's the root password you set during the order process for your VPS which is sent in clear text. It's not the account password.

Sign In or Register to comment.