Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


PSA: Cloudie Networks breached - Page 7
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

PSA: Cloudie Networks breached

1234579

Comments

  • I'd like providers to stop using all the default WHMCS user registration form options if they can't keep the user details secure.

    Only enable a couple of options like Email Address and Full Name. Disable boxes like phone number, address, VAT number, etc.

  • @dosai said:
    Why was op banned?

    I’ll do you one better. Why was digirdp and repuc and awmblablabla given patron provider tags back ?

  • @jmaxwell said:

    @dosai said:
    Why was op banned?

    I’ll do you one better. Why was digirdp and repuc and awmblablabla given patron provider tags back ?

    For DigiRDP it should be easy to check. As far as i remember the requirement was to get off Spamhaus DROP.

  • @yoursunny said:

    @jbiloh said:
    There is no issue with this thread and as of now it will remain open.

    This thread should have new title:
    PSA: user data leaked due to WHMCS vulnerability

    Whmcs module developed by third party or directly by the whmcs?

  • edited December 2023

    MS said:
    I'd like providers to stop using all the default WHMCS user registration form options if they can't keep the user details secure.

    Only enable a couple of options like Email Address and Full Name. Disable boxes like phone number, address, VAT number, etc.

    I very much hate it when phone number is a mandatory field in registration forms. Noone has ever called me. OK, that might be related to the fact that i 99.999% of the time i'll put a valid but never used number there, so if anyone tried i'm very sorry but the person you are calling is not available at present.

    Thanked by 1_MS_
  • @totally_not_banned said:

    MS said:
    I'd like providers to stop using all the default WHMCS user registration form options if they can't keep the user details secure.

    Only enable a couple of options like Email Address and Full Name. Disable boxes like phone number, address, VAT number, etc.

    I very much hate it when phone number is a mandatory field in registration forms. Noone has ever called me. OK, that might be related to the fact that i 99.999% of the time i'll put a valid but never used number there, so if anyone tried i'm very sorry but the person you are calling is not available at present.

    I personally always use the hearest McDonalds address & phone number as my contact information.

  • FatGrizzlyFatGrizzly Member, Host Rep

    @LeroyJ said:

    @yoursunny said:

    @jbiloh said:
    There is no issue with this thread and as of now it will remain open.

    This thread should have new title:
    PSA: user data leaked due to WHMCS vulnerability

    Whmcs module developed by third party or directly by the whmcs?

    3rd party.

    Thanked by 1Levi
  • how did OP get banned?

  • @nillyhan said:
    how did OP get banned?

    With pushing this ban button. Example:

  • @Mumbly you might want to check your blurring effort. We still can see who is about to be banned.

    Thanked by 1bench
  • FatGrizzlyFatGrizzly Member, Host Rep

    Banned OP told me that he was banned after linking to LES

  • MumblyMumbly Member
    edited December 2023

    @totally_not_banned said: @Mumbly you might want to check your blurring effort. We still can see who is about to be banned.

    I noticed that too and expected someone to mention it, but it's actually sample from Vanilla forum kb article:

    https://success.vanillaforums.com/kb/articles/1428-ban-users

    Thanked by 1totally_not_banned
  • @FatGrizzly said:
    Banned OP told me that he was banned after linking to LES

    Well, kind of, i guess? The link is still there. It's a couple pages back in this thread.

  • MumblyMumbly Member
    edited December 2023

    @FatGrizzly said: Banned OP told me that he was banned after linking to LES

    Well, he's always banned after "something" as that's his 10th or something ... banned account.

  • Banned or not he brought a good fuss here: DROP list member, VPN provider which is criminal and more. It was good topics.

  • @LeroyJ said:
    Banned or not he brought a good fuss here: DROP list member, VPN provider which is criminal and more. It was good topics.

    are @skin and @Mustafa actually same person or it's a kind of joke that grew on everyone here?

  • @nillyhan said:

    @LeroyJ said:
    Banned or not he brought a good fuss here: DROP list member, VPN provider which is criminal and more. It was good topics.

    are @skin and @Mustafa actually same person or it's a kind of joke that grew on everyone here?

    The real question is: Does anyone really care that much? I mean, they might very well be but would it make a lot of difference to you or me?

  • @LeroyJ said:
    he brought a good fuss here: DROP list member

    So did anyone check if DigiRDP is off of DROP? I mean they should be if they have their title back, right?

  • DPDP Administrator, The Domain Guy

    @jmaxwell said:

    @dosai said:
    Why was op banned?

    I’ll do you one better. Why was digirdp and repuc and awmblablabla given patron provider tags back ?

    When did this happen?

    I just checked and they don’t seem to have it.

  • @DP said:

    @jmaxwell said:

    @dosai said:
    Why was op banned?

    I’ll do you one better. Why was digirdp and repuc and awmblablabla given patron provider tags back ?

    When did this happen?

    I just checked and they don’t seem to have it.

    At this rate, soon.

  • DPDP Administrator, The Domain Guy

    @jmaxwell said:

    @DP said:

    @jmaxwell said:

    @dosai said:
    Why was op banned?

    I’ll do you one better. Why was digirdp and repuc and awmblablabla given patron provider tags back ?

    When did this happen?

    I just checked and they don’t seem to have it.

    At this rate, soon.

    Sorry, I don’t get it, what do you mean soon?

    You mentioned/asked “why was digirdp and repuc and awmblablabla given patron provider tags back?”

    When you said “back”, when did it happen?

  • @DP said:

    @jmaxwell said:

    @DP said:

    @jmaxwell said:

    @dosai said:
    Why was op banned?

    I’ll do you one better. Why was digirdp and repuc and awmblablabla given patron provider tags back ?

    When did this happen?

    I just checked and they don’t seem to have it.

    At this rate, soon.

    Sorry, I don’t get it, what do you mean soon?

    You mentioned/asked “why was digirdp and repuc and awmblablabla given patron provider tags back?”

    When you said “back”, when did it happen?

    Sorry, I missed to add /s

  • TrKTrK Member
    edited December 2023

    Here's an honest question i want to ask, LET confirmed the leak on 17/18th of December why wasn't Cloudie asked to inform the customers and why wasn't there a topic regarding Cloudie and maybe some more Patron providers being compromised, LET being in a position and management already aware lf the breach could have just issued a security advisory. Why the customers were informed so late does it takes 10 days to verify a data breach? Despite i have an account with Cloudie I don't like how things went.

    Thanked by 1dedotatedwam
  • @TrK said: why wasn't Cloudie asked to inform the customers

    He informed his customers but downplayed it as a "unauthorized access" and claimed that "we do not have any reason to believe that any personal or payment data has been breached".

    Being honest is way better than lying to your customers and trying to sweep it all under the rug.

    Thanked by 1sillycat
  • Pretty disappointed with @SmartHost for not chiming in after they were mentioned as being affected too.

  • MS said:
    I'd like providers to stop using all the default WHMCS user registration form options if they can't keep the user details secure.

    Only enable a couple of options like Email Address and Full Name. Disable boxes like phone number, address, VAT number, etc.

    why? which parts of those are not part of the public domain? You cant or shouldnt provision a service to someone otherwise?

  • Is OP the hacker and or was hostsolutions hacked by the same group/person?

  • @ascicode said: Is OP the hacker and or was hostsolutions hacked by the same group/person?

    OP is not the hacker

  • mgcAnamgcAna Member, Host Rep

    I wonder if something similar happens to WP official store, probably half of the internet would be hacked.

  • jarjar Patron Provider, Top Host, Veteran

    @dahartigan said:
    Pretty disappointed with @SmartHost for not chiming in after they were mentioned as being affected too.

    Were they confirmed to be hit? I might have missed it, I’ve got more on my plate than I can handle trying to keep up with this topic.

    If it wasn’t confirmed yet I wouldn’t trust it. The attacker may be at best intermittently trustworthy.

    Thanked by 1dahartigan
Sign In or Register to comment.