Hier direct Visa kaart laten blokkeren... tis mss overkill maar liever zeker zijn..
Afdrukvoorbeeld
Ben benieuwd hoe ze de Twitter account terug hebben gekregen. In eerdere posts gaven ze nog aan hier hulp voor te zoeken.
ER is een standaard procedure om je account terug te krijgen (zie https://support.twitter.com/articles/185703 ). Mogelijk hebben zij gereageerd.
Dat zal het inderdaad wel zijn. Wel logisch dat ze ongeduldig werden als er zoveel dingen tegen zitten waar je voor het overgrote deel niet veel meer aan kan doen.
E-mail van WHMCS:
Dear Customer,
This is a follow up to the Urgent Security Alert email sent earlier this week. As you will be aware from that, we were the victim of a malicious attack which has resulted in our server being accessed, and our database being compromised.
As a security precaution, we are expiring all passwords for our client area. In order to restore access to your account, please visit the following url to reset your password:
https://www.whmcs.com/members/pwreset.php
We have restored all essential services except for our forums, and resumed normal operations as quickly as possible in order to keep licensing and support channels open. We are still actively working to restore the forums, and we expect them to return to operation soon.
A full security audit and hardening was undertaken immediately following the breach, and the site remains safe to use. It is important to note that the breach we experienced was the result of a social engineering attack, and not the result of a hack or a breach in the WHMCS software.
We continue to experience a distributed denial of service attack, which has caused disruption to our public facing site. We are in the process of moving to a more expansive infrastructure which should mitigate this type of attack in the future. With this move, we will have a much stronger setup with additional layers of security, and these upgrades to our infrastructure will ultimately mean that our servers, and your data, will be better protected than ever before.
Please be aware, that in order to deliver these security upgrades, we expect some very brief downtime during the migration process. We apologize in advance for any inconvenience this may cause.
While we are all currently focused on security, we would like to take this opportunity to ask everyone to read our Security Guide @ http://go.whmcs.com/22/security
While it would be ideal for all steps to be followed, we recommend that you at least rename (http://go.whmcs.com/23/securityfolder), and apply IP protection (http://go.whmcs.com/24/securityip) and/or password protection (http://go.whmcs.com/25/securityadmin) to the admin directory.
We are continuing to work tirelessly to resume normal service and regain your trust. On behalf of everyone at WHMCS please accept my apologies for the inconvenience and we thank you for your support.
----
Matt
WHMCS Limited
www.whmcs.com
Spammers hebben de database inmiddels ook gebruikt :')
Citaat:
Good afternoon,
would be interested in processing payments by Credit Card in your WHMCS?
You can do this through our HiPay Gateway for integration with WHMCS.
HiPay (hipay.com), is a company like Paypal, but enables its customers to pay by Credit Card and other 15 different types of payments (easy account setup without waiting or approval time). We provide you with a gateway that allows you to use HiPay in your WHMCS, similarly to how you probably already use Paypal.
We offer full support in setting up the gateway to your whmcs and the possibility of testing, totally free, the gateway for 7 days.
For a free license follow this link: .
Any difficulty in the installation please contact us, which will help you in everything you need for free. If you prefer support by msn: .
That is all.
Best regards,
Frogost.com
Om die reden maak ik meestal andere e-mail adressen aan, maar dat deed ik pas nadat ik WHMCS had genomen en daarna nooit meer aangepast:(
Helaas werkt dat niet altijd want door te registreren bij Moneybookers krijg je ook spam en dat kan je niet blokkeren helaas.
Inmiddels is het forum ook weer online. Geen nieuwe info, maar ze hebben een Q & A online gezet:
Compromise Q&A
Compromise Q&A
Q. Where can I find the details about what happened?
We have been regularly posting on our blog all week to keep users updated as soon as new details have become available, so please refer to http://blog.whmcs.com
Q. Why can't I login to your client area?
As a security precaution, we have expired all passwords for our client area. In order to restore access to your account, please visit the following url to reset your password: https://www.whmcs.com/members/pwreset.php
Q. I tried to access your site but it was down again, what's happened?
Since the initial attack on Monday, we have been experiencing a continuous distributed denial of service attack. This has caused disruption to our public facing site(s) and intermittent access problems.
Q. I've heard you host everything on one server, is that true?
No, we have our primary server which hosts our WHMCS installation and then a secondary server which hosts third party software's such as this forum, the blog and the documentation resources.
Q. How did the user gain access to your server?
Access was gained using social engineering.
Q. What is "social engineering"?
Put simply, it is the art of manipulating people into performing actions or divulging confidential information. In our case, it was a user impersonating our owner with our managed web hosting provider.
Q. What information was taken?
Our database was compromised, and therefore names, addresses & credit card information is at risk.
Q. What should I do?
You should change all passwords that you have used with us, both for the client area and provided via support tickets. Also if you have ever paid us via credit card directly (not through PayPal), then we recommend notifying your card company that your card details may have been stolen.
Q. Is there anything else I should look out for?
You should beware of criminals pretending to be from either WHMCS, your bank or other trusted companies.
Q. What are you doing to ensure this doesn't happen again?
We are in the process of moving to a new more expansive hosting infrastructure. This will happen next week. In the meantime, a full security audit and hardening was undertaken immediately following the breach, and our site remains safe to use. It is important to note that the breach we experienced was the result of a social engineering attack, and not the result of a hack or a breach in either the server or WHMCS software.
http://forum.whmcs.com/showthread.ph...romise-Q-amp-A
Hmm, handig. Hier gebruiken we geen moneybookers... Maar had eigenlijk mijn prive mailadres best wel spam vrij, beetje jammer.
@Huib: Misschien handig om de links van de spammerT te (laten) verwijderen.
Yep... Ik had het gepost en dacht toen al de link kan beter weg... maar kon de edit knop nergens vinden
Een van de boefjes is inmiddels opgepakt: http://news.softpedia.com/news/UGNaz...h-272565.shtml