Jump to content

Unauthorised Access to WHMCS Admin ! Please Help me Fast !


Recommended Posts

Dear Sir My WHMCS Got Hacked Today !

Actually , a client placed a order for shared hosting and paid for it ! When I woke up today and checked his order in whmcs I saw no order found and when I checked transactions then transaction shows but client name not shows and when I go to that invoice I'd it shows no invoice

and when I checked my email , I received an email shows an invalid login attempt of admin from username root.

I checked Logs and I saw these logs -

Created Client viral patel - User ID: 259

Client Deleted - ID: 259

Single sign-on Completed: 'Hostt' - Server ID: 1

Server Modified: 'HostBet' - Changes: Password Modified - Server ID: 1

all of these logs are from ' local ' user 

I checked whmcs but I did not found any local or root administrator.

anyone please help me.

Edited by Piyush Mahes
Link to comment
Share on other sites

@Piyush Mahes

Have you changed your WHMCS and server password once you have identified the breach?

If no, try changing the login credentials with strong passwords and make sure that you have full control.

Once you retain the control run a malware/antivirus scan to check if your systems are secured or compromised.

And also make sure that all your themes/plugins and other kinds of stuff hosted on your server is not cracked/nulled.

Link to comment
Share on other sites

Change password and If you are not using 2Factor authentication, start it now, at list for Administrator. Also activate 2Factor authentication on your cpanel\WHM.

Analyse all your change logs, to find suspect action.
Use ht.access login access and also all of WHMCS Further Security Steps

Try Cloudflare, most of big and good hosting now are offering free cloud-flare plugin.

Using latest version of WHMCS and also modules (hope you are on php 5.6)

Have your backup in place, local and remote.

Take a moment for you, and check what you have being doing wrong and how you could improve and get stronger.

 

 

 

 

Link to comment
Share on other sites

  • WHMCS John changed the title to Unauthorised Access to WHMCS Admin ! Please Help me Fast !

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated