amuck-landowner

URPad Claiming new WHMCS Vuln

iWF-Jacob

New Member
Verified Provider
I certainly have yet to hear anything. Though I'll definitely be keeping an eye out for it now that it's been mentioned.
 

Francisco

Company Lube
Verified Provider
Maybe it's a new exploit in the SolusVM module?

It's the only thing I can make sense of since they left WHMCS online w/o issue.

Does anyone know if they were using the official module?

Francisco
 

markjcc

New Member
Maybe it's a new exploit in the SolusVM module?


It's the only thing I can make sense of since they left WHMCS online w/o issue.


Does anyone know if they were using the official module?


Francisco
http://docs.solusvm.com/release_versions_stable

The last update for the official stable version was on the date of April 22, 2014

The last thing that I can put my finger on was they're either using the beta module or it's got to do something with the new WHMCS update 
 

Francisco

Company Lube
Verified Provider
http://docs.solusvm.com/release_versions_stable

The last update for the official stable version was on the date of April 22, 2014

The last thing that I can put my finger on was they're either using the beta module or it's got to do something with the new WHMCS update
If it was purely WHMCS they would block WHMCS I would think.

Given Solus' coding practices it's possible that the WHMCS upgrades really botched things but that's pretty

far fetched.

Francisco
 

George_Fusioned

Active Member
Verified Provider
I just contacted both WHMCS and SolusVM and none of them is aware of any exploit at this point.
 
Last edited by a moderator:

MartinD

Retired Staff
Verified Provider
Retired Staff
I've seen no-one else mention this apart from UrPad.. and there's been no hints anywhere else like WHT... would suggest something local to be. Maybe more IPMI related problems?
 
We haven't heard about anything yet too. Many of our customers are using both WHMCS and SolusVM, sometimes combined with our modules, but no one has reported anything yet. And most likely no one will.
 

MannDude

Just a dude
vpsBoard Founder
Moderator
Well, that was strange. I guess it's good news that there wasn't a new vulnerability out or anything. Hope they got whatever it was sorted out.
 

definedcode

New Member
Verified Provider
They should probably confirm it's a vulnerability before putting something like that out into the wild. At least they got it fixed.
 
Top
amuck-landowner