Jump to content

Security Notice Email?

Recommended Posts

(realized after I posted I put this in the wrong section of the forums. Sorry, please move)


Did the Urgent Security notice hit everybody's email before it got posted here?


I wanted to make sure it was a legit email before I followed it's instructions.


Dear WHMCS User,




There is a chance that you may have downloaded V3.5.1 at the time when the files were present and so may have inadvertently uploaded them to your server. As a precaution we are asking all customers to check for, and remove, the following files if they are found to be present in your WHMCS folders:


(REMOVED - Refer to email for details)


NOTE: If you used our professional upgrade or installation services to have WHMCS installed or upgraded by us then you will NOT have been affected.







Founder / Developer



Link to comment
Share on other sites

(post should be moved to Client Discussion forum)


I say it is a legit email.


I was affected, but only had one of the files. I had similar named files, but not named exactly as the ones described in the email.


I removed the one file... hopefully no damage was done.



PS. Thank you for letting us know!

Link to comment
Share on other sites

They were sneaky files too. Very similar to real files.

Yes, indeed. I had someone on my account the other day (not because of this, AFAIK) and they hid it in /lib/plugins as functions_xxx.php. (obfuscated the actual name here) So similar it might go unnoticed altogether.

Link to comment
Share on other sites

Wow - this is pretty incredible. I didn't have any of the files myself fortunately.

A big sigh of relief here after checking my WHMCS server. :)


Matt, Please post the MD5 of all file packages so we can be assured of their integrity before installing them to our precious servers! :)

Thumbs up to this suggestion. thumbsup%5B1%5D.gif

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated