jasonmccurry Posted May 21, 2012 Share Posted May 21, 2012 Is the main & client side of the site hacked, it is redirecting to some wierd site and SiteAdvisor said its a bad site? Link to comment Share on other sites More sharing options...
Nix Posted May 21, 2012 Share Posted May 21, 2012 holy ****... Link to comment Share on other sites More sharing options...
bear Posted May 21, 2012 Share Posted May 21, 2012 http://twitter.com/#!/joshthegod Link to comment Share on other sites More sharing options...
jasonmccurry Posted May 21, 2012 Author Share Posted May 21, 2012 Just found out it was a major hacking group named "Ugnazi", don't know what could of happened, the licensing server was down earlier too. WebHostingTalk Thread: http://www.webhostingtalk.com/showthread.php?p=8137810#post8137810 Link to comment Share on other sites More sharing options...
jasonmccurry Posted May 21, 2012 Author Share Posted May 21, 2012 Looks like they are starting to delete this forum now. Link to comment Share on other sites More sharing options...
WHMCS Developer WHMCS Andrew Posted May 21, 2012 WHMCS Developer Share Posted May 21, 2012 The forum linked to images on the main whmcs site. You should hopefully find the forum is loading correctly again Link to comment Share on other sites More sharing options...
XN-Matt Posted May 21, 2012 Share Posted May 21, 2012 I guess it is best to cancel the card stored on your system. If they've got the DB, I'll assume they have the encryption key too. Link to comment Share on other sites More sharing options...
SoHoIT Posted May 21, 2012 Share Posted May 21, 2012 The forum linked to images on the main whmcs site. You should hopefully find the forum is loading correctly again Is my personal data safe? What about all my login details? Paypal? enom? our own WHMCS install? Link to comment Share on other sites More sharing options...
XN-Matt Posted May 21, 2012 Share Posted May 21, 2012 Probably not. Your login details, if you've given them to WHMCS, should be changed immediatlely. None of the information in your WHMCS without this is at risk. Link to comment Share on other sites More sharing options...
Justine Posted May 21, 2012 Share Posted May 21, 2012 WHMCS really need to address this and let us know if any personal information has been jeopardised. Hopefully WHMCS will release an official statement about it soon. Link to comment Share on other sites More sharing options...
laszlof Posted May 21, 2012 Share Posted May 21, 2012 WHMCS really need to address this and let us know if any personal information has been jeopardised. Hopefully WHMCS will release an official statement about it soon. Heh.. They will have to actually fix the issue first. IMO, dont worry about notifying people, sending out updates, whatever. Fix the problem before it gets worse, then let us know what happened. Proper security audits after an attack take time. Link to comment Share on other sites More sharing options...
WHMCS CEO Matt Posted May 21, 2012 WHMCS CEO Share Posted May 21, 2012 I would like to assure everyone we're doing everything we can to identify what has happened here, exactly what's been taken, and get things back online. We will provide further updates as soon as we have them. Matt Link to comment Share on other sites More sharing options...
jameshostit Posted May 21, 2012 Share Posted May 21, 2012 Hi Matt, Can't find the best way to contact you other than this. If you need any assistance or anything at all please contact me and I'll see what I can do albeit a server, hosting etc. James Greig Non corporate email under the circumstances: - email: jaygreig86@gmail.com Link to comment Share on other sites More sharing options...
niels Posted May 21, 2012 Share Posted May 21, 2012 Please prioritize the license server. We can't login to the Administration area currently. Link to comment Share on other sites More sharing options...
SoHoIT Posted May 21, 2012 Share Posted May 21, 2012 forum compromised too now?? Link to comment Share on other sites More sharing options...
WHMCS Support Manager WHMCS John Posted May 21, 2012 WHMCS Support Manager Share Posted May 21, 2012 Hi, Whilst the forums and documentation are hosted separately from our website the images/css are linked from there so until that's restored it won't be pretty but still functional. Please refer to the following thread for updates: http://forum.whmcs.com/showthread.php?t=47644 Link to comment Share on other sites More sharing options...
Huib Posted May 21, 2012 Share Posted May 21, 2012 Only the header is broken since that points to whmcs.com The box resolves to a other IP Link to comment Share on other sites More sharing options...
SoHoIT Posted May 21, 2012 Share Posted May 21, 2012 reason I ask is because my forum session timed out and when I logged back in it asked me to click on some weird characters. - looked a bit suspicious!! Link to comment Share on other sites More sharing options...
darksuntr Posted May 21, 2012 Share Posted May 21, 2012 /http://freeaccount.myorderbox.com page does not open Link to comment Share on other sites More sharing options...
skull87 Posted May 21, 2012 Share Posted May 21, 2012 /https://twitter.com/#joshthegod /https://twitter.com/#ugnazi WHMCS your database has been stolen according to the people that hacked you ugh these guys are idiots. Link to comment Share on other sites More sharing options...
DeanC Posted May 21, 2012 Share Posted May 21, 2012 Your twitter has been compromised too. Link to comment Share on other sites More sharing options...
Andrew-FH Posted May 21, 2012 Share Posted May 21, 2012 Matt don't be stupid here, just tell us are our credit card details safe, are they encrypted, if yes, is that encryption breakable ? the worrying part is they are going to leak your WHMCS database which includes a ****lin huge list of WHMCS clients, and we are gonna b fked up, sorry to be abusive here, but this situation is no less than epidemic breakout here. Any words on banking details from you ? Link to comment Share on other sites More sharing options...
XN-Matt Posted May 21, 2012 Share Posted May 21, 2012 Why risk it. Cancel the card and get it re-issued. Yes, names, email addresses the like may be leaked but for many that might be public "business" information anyway. The password may be reversible but this only teaches everyone to never use the same password/email combo for public sites. Assume the worst and act as you would if everything was out there. Link to comment Share on other sites More sharing options...
Moc Posted May 21, 2012 Share Posted May 21, 2012 Regardless of the database being leaked or not, change all passwords that WHMCS may have or may have had. That includes securing credit card details, possibly contacting your bank and alerting them of possible fraud or just cancel and re-issue anyway. Be pro-active, not reactive. Link to comment Share on other sites More sharing options...
WHMCS CEO Matt Posted May 21, 2012 WHMCS CEO Share Posted May 21, 2012 Hi Andrew, Until we know for sure it would be irresponsible of us to say credit card details are safe. They are encrypted, but encryption is always reversable. As per our announcement post, it is worth assuming that any details you've submitted to us via tickets are at potential risk, so if you've recently sent us login details for either WHMCS or Hosting/FTP and haven't yet changed them since that time, then it would be advisable to change those. At this time there is still nothing to suggest that this compromise actually originated through the WHMCS software itself. This was not merely a WHMCS system access, and in our WHMCS, we do not have it hooked up to our server. Matt Link to comment Share on other sites More sharing options...
Recommended Posts