WHMCS Main Database Compromised

copxxx

Registered Member
Joined
May 21, 2008
Messages
57
Reaction score
14
whmcslogowhite.png


As we already know WHMCS's database has been compromised.

Official email from WHMCS
Unfortunately today we were the victim of a malicious social engineering attack which has resulted in our server being accessed, and our database being compromised.

To clarify, this was no hack of the WHMCS software itself, nor a hack of our server. It was through social engineering that the login details were obtained.

As a result of this, we recommend that everybody change any passwords that they have ever used for our client area, or provided via support ticket to us, immediately.
Regrettably as this was our billing system database, if you pay us by credit card (excluding PayPal) then your card details may also be at risk.

This is just a very brief email to alert you of the situation, as we are currently working very hard to ensure everything is back online & functioning correctly, and I will be writing to you again shortly.

We would like to offer our sincere apologies for any inconvenience caused. We appreciate your support, now more than ever in this challenging time.

Interesting situation, let's see the facts.

What we know for sure

1. Our server was compromised by a malicious user that proceeded to delete all files
2. We have lost new orders placed within the previous 17 hours
3. We have lost any tickets or replies submitted within the previous 17 hours

What may be at risk

1. The database appears to have been accessed
2. WHMCS.com client area passwords are stored in a hash format (as with all WHMCS installations by default) and so are safe
3. Credit card information although encrypted in the database may be at risk
4. Any support ticket content may be at risk - so if you've recently submitted any login details in tickets to us, and have not yet changed them again following resolution of the ticket, we recommend changing them now.

What do you think guys?
 
Just got this email aswell,Guess I need to change my credit card today -.-
 


The data leaked included over 500, 000 compromised customers emails and ips and even credit cards.
On top of this the twitter account of WHMC was also hacked and post several tweets, explaining also the reasons for the hack
.
 
Last edited:


The data leaked included over 500, 000 compromised customers emails and ips and even credit cards.
On top of this the twitter account of WHMC was also hacked and post several tweets, explaining also the reasons for the hack
.

Thats what I call superb security! :tumblewee

WHMCS couldn't afford real coders & admins as I can see.
 
3. Credit card information although encrypted in the database may be at risk

They are downplaying this. It 's obvious that since the attackers had full access, they didn't get the just db, they also snatched the code that decrypts the encrypted data ;)
 
social engineering---I don't buy thing. What they mean that someone cheated with an admin and made him give his password?
 
I've heard some rumors about the "hacker" skid knew the owner last four CC number and with that he could get an access from Hostgator ^^ lol u might think now what a fool staff is there.
 
Wow this is terrible.

Does this mean that anyone who has ever payed for something with CC through the WHMCS platform may have their cc info stolen?
 
and now main question is who will cover my expenses for new debit card.... WHMCS? do i have a right to ask from them? and lowest fastest expenses are 60$ for one debit card... f... retards... and why they did not bought a server and collocate it like every big company out there...
 
social engineering---I don't buy thing. What they mean that someone cheated with an admin and made him give his password?

This is what the lead developer (Matt Pugh) wrote:

Following an initial investigation I can report that what occurred today was the result of a social engineering attack.

The person was able to impersonate myself with our web hosting company, and provide correct answers to their verification questions. And thereby gain access to our client account with the host, and ultimately change the email and then request a mailing of the access details.

This means that there was no actual hacking of our server. They were ultimately given the access details.

http://blog.whmcs.com/?t=47660

So they're claiming their host (Hostgator) handed over the admin access.
 
Wow, thank god I had paid for that with PayPal.

I'm still amazed that they were able to impersonate them that easily
 
Does this mean if I have a reseller account with Hostgator my c.c. has been compromised????
 
Does this mean if I have a reseller account with Hostgator my c.c. has been compromised????

No, the hackers apparently had access only to WHMCS's hostgator account, not all hostgator accounts.
 
Hilarious I must say. ClientExec should use this to their advantage.

PS. It seems that their database was leaked online which means anyone and everyone has access to it. Would definitely request a new credit card if I was their direct customer.
 
Last edited:
Slightly off topic but still relevant..

It amazes me how many big companies use such poor hosts like HostGator for their sites.

HostGator don't have the best reputation for security or service, and with companies such as WHMCS that provide services speicifically tailored to web hosts you'd think that they would know better.

Anyone know the reasons for the attack that were posted on the twitter account?
 
Sadly this happens to the bigger players in fields e.g. when the PS3 network was compromised.

Fortunately I never paid them direct for anything and never gave them a password. Let's hope nothing else comes from this....
 
People, you don't have to freak out that easily.

This hack was at WHMCS' own database, it doesn't affect you even if you've paid for something via WHMCS in the past, the WHMCS you've accessed in the past is not connected to the main HQ or smt. Chill out.
 
People, you don't have to freak out that easily.

This hack was at WHMCS' own database, it doesn't affect you even if you've paid for something via WHMCS in the past, the WHMCS you've accessed in the past is not connected to the main HQ or smt. Chill out.

As a result of this, we recommend that everybody change any passwords that they have ever used for our client area, or provided via support ticket to us, immediately.
Regrettably as this was our billing system database, if you pay us by credit card (excluding PayPal) then your card details may also be at risk.

Please see above quote.
 
Back
Top