slim Posted October 25, 2013 Share Posted October 25, 2013 yeah, saw the blog post but didnt see any forums posts about todays? 0 Quote Link to comment Share on other sites More sharing options...
wsa Posted October 25, 2013 Share Posted October 25, 2013 http://forum.whmcs.com/showthread.php?80586-new-WHMCS-exploit 0 Quote Link to comment Share on other sites More sharing options...
slim Posted October 25, 2013 Share Posted October 25, 2013 Probably because noone bothered to put the version number or date in the title. - - - Updated - - - 'new' doesnt really mean anything with WHMCS exploits 0 Quote Link to comment Share on other sites More sharing options...
spinnas Posted October 25, 2013 Share Posted October 25, 2013 it's called look before you post...don't blame other people because you're too incompetent 0 Quote Link to comment Share on other sites More sharing options...
olijo Posted October 25, 2013 Share Posted October 25, 2013 Today i discover the exploit and the "fix" in the blog, how is it possible whmcs don't send an email to all customer to report the problem. Because you don't have the fix ? I prefer disable all whmcs install instead of having all of my business ruined... This month we had 5 security patch ! Hey guys, what are you doing seriously ! Sure cPanel will appreciate this quality of work... 0 Quote Link to comment Share on other sites More sharing options...
djpete Posted October 25, 2013 Share Posted October 25, 2013 I have done this as explained here... As you may be aware, a security issue has been published within the last hour which allows for information disclosure. We are aware of the issue and are investigating it, and will be issuing a fix for this issue along with any others we discover during our targeted investigation shortly. In the meantime disabling the Mass Payment feature voids the immediate threat. You can do this by de-selecting the "Enable Mass Payment" checkbox in Setup > General Settings > Invoices and saving. Please watch our blog, facebook and twitter feeds to receive the latest updates. 0 Quote Link to comment Share on other sites More sharing options...
Blueberry3.14 Posted October 25, 2013 Share Posted October 25, 2013 are you even a user of the software... I seem to see allot of first time people commenting and I normally see that as trolling from other companies I wondered about that, too. Yeah, 3 in a row is bad, but honestly... May 2012 when they got hacked was way worse, PR wise. That was a cluster-and-a-half. 0 Quote Link to comment Share on other sites More sharing options...
slim Posted October 25, 2013 Share Posted October 25, 2013 I did. But it didn't stand out due to there being lots of new exploits. 0 Quote Link to comment Share on other sites More sharing options...
malfunction Posted October 25, 2013 Share Posted October 25, 2013 When it makes it possible to log in as an admin, and use that access to do so. That's one way. OK so if you set write permissions on /downloads there's a file browse/upload form is there? I don't allow write access there (or unauthorized folks to roam around with admin privileges) so I've never seen that. Would make sense if that's how it works though, upload a PHP shell script through that and it's game over. This post seems to suggest anther vector though http://forum.whmcs.com/showthread.php?80410-Was-my-installation-compromised&p=343690#post343690 which is rather alarming I have to say. Just trying to get a handle on how to mitigate all this, the lack of disclosure and transparency from WHMCS is quite shocking. Better information to be had on WHT... 0 Quote Link to comment Share on other sites More sharing options...
tomb Posted October 25, 2013 Share Posted October 25, 2013 (edited) Oh man, I am getting really upset about this software policy! I can’t agree BryanB more on that. We are doing serious business with WHMCS. It’s not game! A official roadmap or statement for future security measurements is essential. Hot fixes should be more exception than rule! WHMCS should spend more time on quality instead of providing us with new features. I don’t have time to check Facebook, Twitter and Blog section all the time. With the latest patch releases we don’t have enough time for testing new releases. I hope the new patch doesn't break our system. Thinking about alternatives too. Edited October 25, 2013 by tomb spelling 0 Quote Link to comment Share on other sites More sharing options...
Infopro Posted October 25, 2013 Share Posted October 25, 2013 yeah, saw the blog post but didnt see any forums posts about todays? All related threads have been merged into this one. 0 Quote Link to comment Share on other sites More sharing options...
penguin Posted October 25, 2013 Share Posted October 25, 2013 I see that v5.2.11 incremental has now been published, however it unfortunately does not update the reported version for the installation and still shows 5.2.10 after the upgrade 1 Quote Link to comment Share on other sites More sharing options...
Blueberry3.14 Posted October 25, 2013 Share Posted October 25, 2013 All related threads have been merged into this one. There were some from today's exploit and some from the exploit a few days ago...but at least now I know what happened (to the post I was reading, AS I was reading it! LOL!). Adding [MERGED] to the subject (like the support tickets do) woulda been nice. 0 Quote Link to comment Share on other sites More sharing options...
tomb Posted October 25, 2013 Share Posted October 25, 2013 I see that v5.2.11 incremental has now been published, however it unfortunately does not update the reported version for the installation and still shows 5.2.10 after the upgrade confirmed. whmcs_v5211_incremental doesn't update the reported version. It's still showing 5.2.10 1 Quote Link to comment Share on other sites More sharing options...
Blueberry3.14 Posted October 25, 2013 Share Posted October 25, 2013 well, do you guys know any good alternative? A real modular alternative? not boxbilling.. Not that I've found, no. Some of the alternatives are worse. 0 Quote Link to comment Share on other sites More sharing options...
Dicko_md Posted October 25, 2013 Share Posted October 25, 2013 Hi Does any one else have the issue where its still saying the old version number after updating to 5.2.11 ? I uploaded the zip file and overwritten them. I have done by extracting the zip file after rezipping with correct admin folder name and then I did this manually to make sure I did it right. Thanks Martyn 0 Quote Link to comment Share on other sites More sharing options...
tomb Posted October 25, 2013 Share Posted October 25, 2013 (edited) Yes, confirmed! - Removed Link - Edited October 25, 2013 by Infopro URLs Removed - Threads Merged 0 Quote Link to comment Share on other sites More sharing options...
Dicko_md Posted October 25, 2013 Share Posted October 25, 2013 Hi Thanks for that. Its the quickest Ive updated whmcs due to whats been happening and then I thought id discovered it but obviously not lol 0 Quote Link to comment Share on other sites More sharing options...
Si Posted October 25, 2013 Share Posted October 25, 2013 (edited) 5.2.12 patch applied. Now I get: Your Version 5.2.12 Latest Version 5.2.11 You should upgrade to the latest version....... UPDATE: Must have just needed refreshing......showing correct now Edited October 25, 2013 by Si 0 Quote Link to comment Share on other sites More sharing options...
tomb Posted October 25, 2013 Share Posted October 25, 2013 Thanks WHMCS!! They've just updated the Security Advisory Blogpost. Don't be confuse. Now we are on 5.2.12 http://blog.whmcs.com/?t=80615 UPDATE: We've identified a missing file in 5.2.11 which causes the version number not to increment. All security related enhancements are present. We will be updating this post again with version 5.2.12 which will contain the complete change set. Thank you for you patience. 0 Quote Link to comment Share on other sites More sharing options...
tomb Posted October 25, 2013 Share Posted October 25, 2013 (edited) Cross posting: - Removed Link - Edited October 25, 2013 by Infopro URLs Removed - Threads Merged 0 Quote Link to comment Share on other sites More sharing options...
Redsign Posted October 25, 2013 Share Posted October 25, 2013 Using IFTTT you can get an email whenever WHMCS posts any blog post. Details here - http://forum.whmcs.com/showthread.php?80622-How-to-Receive-an-Instant-Email-whenever-WHMCS-adds-a-new-blog-post&p=344010#post344010 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.