|
#1
|
|||
|
|||
|
Hi all,
I receive support and sales tickets through my whmcs usually. I have the latest version of WHMCS. from few days, i am receiving strange tickets. I am copying them here now. Want to know what does it exactly mean and of course what should I do to avoid them? gggg ggggggggggggggggggg@hotmail.com ---------------------------- IP Address: 178.80.183.1 |
|
#2
|
||||
|
||||
|
Quote:
Please edit your post and remove the exploit code. This exploit has been discussed for months at the whmcs forum. There is much information available at forum.whmcs.com on this topic. I suggest you visit that forum. If you applied the patch that was made available some months back prior to these hack attempts, you are ok. If you didn't apply it, you have likely been hacked. See forum.whmcs.com for details.
__________________
- David |
|
#3
|
|||
|
|||
|
|
|
#4
|
||||
|
||||
|
Thanks I didn't see it. I just wanted to show others what the file contains.
Regards, George B. |
|
#5
|
||||
|
||||
|
Quote:
![]() Showing exploit code to complete strangers, is unfortunately a bad idea. You are essentially giving someone the knowledge of how to hack.... possibly thousands of sites. It is perhaps better to describe what an exploit can do in general terms instead of publicly showing how to do it.
__________________
- David |
|
#6
|
||||
|
||||
|
Quote:
When you are on dedicated services (like dedicated server) you are on your own. You have to take control of whatever is uploaded to server. If you are doing paid wehhosting, the problems are not so many, maybe with some outdated software (WordPress, Joomla etc), and you have to force the user to update their software installed. But when you are doing free webhosting it is another thing, more complicated and more problems (if you don't have control). If you don't pay attention to your server logs, what users are doing etc, soon your server IP will be blacklisted and almost major web hosting will block emails from any blacklisted IP. I can talk about this for hours because I did free webhosting and I have seen a lot of things. One small example is a PHP script hidden in a image file. So the abuser is uploading the image file (jpg, png etc) and you'll say there is no problem, and inside this image is in fact hidden a phpshell and can be a short way to server overload, or worst hack. So, what I'll suggest is never trust a user (if his email is coming from a free provider, his info is sounds fake) and the most important thing check your logs. I am talking here about dedicated services. Another thing, In my opinion there is not a real interest to stop abusers, big companies are doing nice money from server setup, anti-spam configurations etc. ![]() Regards, George B. Last edited by freeman; 01-17-2012 at 09:41 AM. |
|
#7
|
||||
|
||||
|
George, this is a current hack for WHMCS , which has caused problems for many sites. It is not an old hack.
__________________
- David |
|
#8
|
||||
|
||||
|
Quote:
If you configure your mod_sec to block this is not a problem. Regards, George B. Last edited by freeman; 01-18-2012 at 06:56 AM. |
|
#9
|
||||
|
||||
|
Hello,
This code is an exploit of which WHMCS made a patch for over a month ago. If you've installed the patch you'll be safe but it won't stop people trying it. This exploit was specific to Smarty which is the template system WHMCS is built with. It also effected a close competitior Hostbillapp.com. I've helped a lot of people who've been hacked as a result of this. If you're unsure whether you've been hacked or not, common files that I've seen uploaded by the hackers use names such as red.php 0.php indexx.php If you do find out that you've been hacked there is a good post on the WHMCS forums that explains what to do. Jack
__________________
█ Zomex - The best WHMCS templates - Admin-based SETTINGS AREA! █ A complete WHMCS Setup service including automatic cPanel account creation! █ View our clients testimonials about our WHMCS services > WHMCS Testimonials |
|
#10
|
||||
|
||||
|
Quote:
The hack is a result of WHMCS previously allowing PHP to be executed in support tickets using {php} {/php} A lot of people from a mix of hosting companies have been hacked which could have been avoided by simply installing WHMCS's security patch.
__________________
█ Zomex - The best WHMCS templates - Admin-based SETTINGS AREA! █ A complete WHMCS Setup service including automatic cPanel account creation! █ View our clients testimonials about our WHMCS services > WHMCS Testimonials |
![]() |
| Bookmarks |
«
Previous Thread
|
Next Thread
»
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| phpMyAdmin hack attempts | LittleTiger | Security Issues | 6 | 05-22-2011 03:36 PM |
All times are GMT -5. The time now is 09:59 AM.











