rke211 Posted June 18, 2011 Share Posted June 18, 2011 Right im wondering if anyone else has this problem so i have the most uptodate version of whmcs installed and i go on every so often and its been hacked my username has been changed to root and there on my account ordering stuff thankfully i dont tend to keep money in the domain register for this reason.... So i even have a cpanel password over the admin folder which which i changed the name of and there still getting in any ideas? Id really like to stop this... 0 Quote Link to comment Share on other sites More sharing options...
laszlof Posted June 18, 2011 Share Posted June 18, 2011 You should figure out the entry point first, I doubt its WHMCS. If you're not capable of finding this out, you should hire someone who is. 0 Quote Link to comment Share on other sites More sharing options...
m8internet Posted June 18, 2011 Share Posted June 18, 2011 If you are setting the password locally, then it most likely an intrusion on that local computer or exception on the host Have any other passwords that you use changed? If not, then it is the host If they have then it is the local computer Check your WHMCS installation that there is only one administrator, yourself If there are others, then disable them 0 Quote Link to comment Share on other sites More sharing options...
zomex Posted June 18, 2011 Share Posted June 18, 2011 I agree with Frank, it's highly unlikely to be WHMCS especially if you're running the latest version. Are you using shared hosting? 0 Quote Link to comment Share on other sites More sharing options...
Pipert Posted June 19, 2011 Share Posted June 19, 2011 Right im wondering if anyone else has this problem so i have the most uptodate version of whmcs installed and i go on every so often and its been hacked my username has been changed to root and there on my account ordering stuff thankfully i dont tend to keep money in the domain register for this reason.... So i even have a cpanel password over the admin folder which which i changed the name of and there still getting in any ideas? Id really like to stop this... I've never had this issue using WHMCS. If you have SSH access on the server, you might want to check the Apache logs to see if you can catch the culprit. Are you running any other scripts on the same hosting account? 0 Quote Link to comment Share on other sites More sharing options...
rke211 Posted June 19, 2011 Author Share Posted June 19, 2011 shh access was disabled as this was also my first guess at what it would be and whmcs seems the most likely path in as when i put a cpanel password over the admin folder it stopped for a couple of days till my configuration.php file ended up being empty and i re-uploaded the admin folder to the default directory im waiting to see if it happens again but atm it seems to be fine 0 Quote Link to comment Share on other sites More sharing options...
mikie Posted June 19, 2011 Share Posted June 19, 2011 shh access was disabled as this was also my first guess at what it would be and whmcs seems the most likely path in as when i put a cpanel password over the admin folder it stopped for a couple of days till my configuration.php file ended up being empty and i re-uploaded the admin folder to the default directory im waiting to see if it happens again but atm it seems to be fine Why is your admin folder called admin anyway? Did you read the documentation that the admin folder, for security reasons, should be moved/renamed to something OTHER THAN /admin? Why dont you read up on the section in the documentation under SECURITY??? 0 Quote Link to comment Share on other sites More sharing options...
rke211 Posted June 20, 2011 Author Share Posted June 20, 2011 it was renamed but when i updated it i accidently uploaded the admin folder again without realising im not that stupid to leave it as admin 0 Quote Link to comment Share on other sites More sharing options...
othellotech Posted June 21, 2011 Share Posted June 21, 2011 It sounds like either the server or your local machine are compromised. Format them both and start again. 0 Quote Link to comment Share on other sites More sharing options...
rke211 Posted June 21, 2011 Author Share Posted June 21, 2011 its definetly not my machine as it happened once without me even loging in as another administrator fixed it and after changing the folder and adding a cpanel password it hasnt seemed to happen again so this is why i would think it is whmcs... if it had happened again that might make me think otherwise 0 Quote Link to comment Share on other sites More sharing options...
ckh Posted June 21, 2011 Share Posted June 21, 2011 It doesn't always happen right away. It could be the same day or a week later if you have some sort of keylogger installed on your computer. Most of the time when a client's account is compromised, it's due to a keylogger. The client always insists that it isn't their computer but it's the server. They all eventually will find something on their computer. 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.