Jump to content

Hacked


TheHostHouse

Recommended Posts

Now, first of all... I'm not sure if this is a problem with WHMCS or some other piece of software with a security hole, but I thought I should post here.

 

Our WHMCS got hacked earlier today and the hacker sent out a to be honest, unacceptable email to all clients, I won't go into detail but lets just say it directly insulted them.

 

Now apart from ruining our reputation and client relationships, I am now completely paranoid that it will happen again. I'd also like to know how it happened in the first place. The hacker signed up for a hosting account, and then sent the email. I have no idea how he/she did it, but when I look at the admin log in WHMCS, it shows the username "hacked" as logging in (see image).

 

hackedmh9.png

w819.png

 

Just a warning to everyone out there. His IP address was 86.132.228.82.

Link to comment
Share on other sites

Were these e-mails sent as a Mass E-mail or each one sent individually? In any case, I've disabled Mass E-mail from all Administrator Roles. Is there anyways to remove this feature (Mass E-mail) from the code to prevent it from ever being used?

Link to comment
Share on other sites

The part that makes me go Hmmmmm

is they actually LOGGED into the admin

and did it in one try

 

this makes me wonder who you might have ticked off that knows your general password?

who do you know in London?

 

No one except me knows the password. I've spoken to Matt and he's certain it's not a problem with WHMCS. I hadn't yet followed the furthur security steps in the WIKI to secure the writeable dirs. It's most that likely someone got direct access to the database some other way.

 

And what does me knowing anyone in London have to do with this?

Link to comment
Share on other sites

Did a lot of Google searching... looks like there could be a 0-day exploit in the wild (this sounds exactly like what happened to you - although it looks like this was posted some time ago):

 

Quote:

The 0day lets you edit/add/remove users from the admin table in the WHMCS mysql database

 

once inside the WHMCS as admin, you are free to view client's information ( CC's, Addresses, IP's, Website cPanels, etc... ) and another good part, Root access to the server if the passes aren't hashed in the server management of WHMCS ( they usually aren't )

 

Check out this post of a hacker trying to sell this exploit.:

 

http://209.85.173.132/search?q=cache:YX_hrqs9xDIJ:www.h4cky0u.org/viewtopic.php%3Ff%3D12%26t%3D24283+whmcs+exploit&hl=en&ct=clnk&cd=17&gl=ca&client=firefox-a

 

I would go through the access logs looking for a specially crafted URL ..

 

These guys are some really big assholes. Look at this post selling a compromised WHMCS hosting company:

 

http://209.85.173.132/search?q=cache:YAWT3cUG0u4J:h4cky0u.org/viewtopic.php%3Ff%3D43%26t%3D32689%26view%3Dprevious+whmcs+exploit&hl=en&ct=clnk&cd=27&gl=ca&client=firefox-a

Edited by danami
Link to comment
Share on other sites

If you are worried about application exploits then I suggest you:

 

1. Install a web application firewall like mod_security.

2. Download the mod security 2.5 free rules from http://www.gotroot.com

 

That way exploits will get stopped before they even get to run your application.

 

From reading the post on webhostingtalk it looks like the hacker got in by:

 

Quote: "All I could tell was that he uploaded a file to his hosting account using the cPanel file manager."

 

Probably nothing to do with WHMCS.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated