

Laatst gewijzigd door Yourwebhoster; 23/05/12 om 14:08.
Met vriendelijke groet, Yourwebhoster.eu - Managed VPS diensten met Epyc performance op 100% SSDs
Lees hier de webhostingtalk.nl forum regels en voorwaarden!
Toen ik keek was het alleen erg langzaam, stond geen troep meer op.
Het forum geeft nu een pop-up dat je een wachtwoord en gebruikersnaam moet invoeren om forum.whmcs.com:80 te benaderen.

Status update:
We are continueing to work very hard to recover from the events of the past few days.
To start with, here's a recap of the timeline of events:
Monday 21st
> Alarm raised about breach of primary server
> Access regained to server, security audit performed, and website restored from backup
> Independant company also asked to perform security audit of primary server
> DDOS Attack starts
Tuesday 22nd
> DDOS attack to main server continues throughout the day causing intermittent access issues
Wednesday 23rd
> DDOS attack to main server continues
> DDOS Attack starts towards forum
> Forums are attacked - posts edited. vBulletin used as a point of entry. The forums, the documentation, and the blog are all hosted on a different server, entirely separate from our primary server. So this poses no new risk to our main client database. This issue is ongoing.
Unfortunately credit card details were taken, and we do urge any clients who feel their credit card might have been included in this to take appropriate steps to secure their card. Further investigations have shown that the social engineering attack did not involve the compromising of any email account. This was only done after access to the server had been gained.
We've been working very hard with our web hosting provider to restore and secure services. The DDOS mitigation continues to be ongoing and we are doing everything we can to limit the impact of this.
Our main priority until now has been getting our main site back online, secured, and operational, so that we could bring our WHMCS installation back online to open up a route of communication to you, our users, and start dealing with any questions and concerns as quickly as possible.
As soon as we have things completely back under control, we will be reviewing all our systems and operating procedures, and making changes as and where appropriate. Steps are already in progress to migrate to a new hosting infrastructure as a first priority. This will likely mean some brief downtime in the coming hours.
As I'm sure you can imagine, we are currently receiving a very large number of support tickets and enquiries, and we're doing all we can to answer them as quickly as possible. Your continued patience & support in these testing times is greatly appreciated.
The whole WHMCS team has been working extremely hard, and I'd like to take this opportunity to thank them as well for all their efforts in the past 36 hours.
-- Our Twitter Account remains out of our control. Does anybody know of any way to contact them or get any assistance from their side to regain control? We have got no response to our requests to them in over 36 hours now.
http://blog.whmcs.com/?t=47717
Met vriendelijke groet, Yourwebhoster.eu - Managed VPS diensten met Epyc performance op 100% SSDs
Lees hier de webhostingtalk.nl forum regels en voorwaarden!
Hoe is het nu mogelijk dat er creditcard gegevens gestolen worden!
Volgens de PCI Compliance mag dit toch niet! Ze mogen alle sinds geen volledige nummers bijhouden!
https://www.pcisecuritystandards.org/
never mind![]()
Laatst gewijzigd door Huib; 23/05/12 om 17:56.
En zoals het ernaar uitziet zal WHMCS de problemen blijven houden:
1.The reason for the hack and database leak of the WHMCS was due to the vulnerability WHMCS and "Matt" have. As most of you know the database contains credit cards, Really? Yup. WHMCS, the number 1 Web Hosting Client management company stores your credit card on Hostgator's servers. By Matt hosting this huge domain on Hostgator he made himself and his domain very insecure and that is why we took action and did what we did. It is now 2 days after the attack from us and the site is back up and it still remains on Hostgator after Matt knows it is insecure. Well Matt, guess what... Here at UGNazi We laugh at your security. By releasing your files, we wanted to make it known that we are watching; and will continue to be watching. Stay Frosty.

Met vriendelijke groet, Yourwebhoster.eu - Managed VPS diensten met Epyc performance op 100% SSDs
Lees hier de webhostingtalk.nl forum regels en voorwaarden!
Heb ik overeen gelezen dan![]()
Laatst gewijzigd door phoenix78; 23/05/12 om 18:38.
Waarbij het mij ontgaat wat het nut is om de gegevens te lekken. Als je punt is om Matt/WHMCS iets duidelijk te maken, is dat gelukt. Dit kunnen ze blijven herhalen, totdat Matt zijn security op orde heeft. Het lekken van gegevens is volledig onnodig, en zorgt voor flinke colleteral damage.
Het heeft waarschijnlijk niet een extra nut om het te lekken maar deed hij dat "just for the fun of it". Het nut van al 3 dagen een DDOS op zijn dak gooien mis ik ook een beetje... Als het punt is dat ie weg moet bij hostgator dan zou hij tijd moeten hebben omdat te doen i.p.v achter feiten aan blijven lopen?
True, maar het dwingt anderen ook om preventief hun security aan te scherpen zonder dat ze eerst gehacked moeten worden om 'het punt duidelijk te maken'. Ik denk/hoop dat een hele hoop hosters onder ons eieren voor hun geld kiezen en dus preventief hun belangrijke data een extra security-jasje aangetrokken hebben.
Imho is er geen verschil tussen een hacker die in zijn eentje/clubje de gegevens misbruikt (en dus niet lekt) of een hele reeks wannabees die het doen als het wel gelekt is.
Ze hebben nu ook hun twitter account weer terug. Lijkt nu de goede kant op te gaan, heb vandaag ook geen last van een langzame site bij hun. Alleen het forum blijft onbereikbaar.