Jump to content

cPanel Exploiter Account


Recommended Posts

I see there was an account called cPanel Exploiter set up in our WHMCS installation today. It looks like they were trying to excecute SQL commands by changing the profile settings like such.

Address 1: 'cpanel' to 'AES_ENCRYPT(1,1), address1= (SELECT MIN(username) FROM tbladmins)'

Address 2: 'security' to 'AES_ENCRYPT(1,1), address2= (SELECT MIN(password) FROM tbladmins)'

City: 'test' to 'AES_ENCRYPT(1,1), city= (SELECT MAX(username) FROM tbladmins)'

State: 'hacked' to 'AES_ENCRYPT(1,1), state= (SELECT MAX(password) FROM tbladmins)'

My question is will these attempts to get information be successful? How would I know? We are running WHMCS 7.1.2. I assume these fields are sanitized for SQL commands?

 

Eric

Link to comment
Share on other sites

  • 5 weeks later...
Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated