amuck-landowner

Zopim live-chat may have been compromised.

MannDude

Just a dude
vpsBoard Founder
Moderator
I had a list of WebHostingTalk's 'unanswered' posts open on another screen, and saw:

N4xEYKG.png

Clicked on it, thread was removed and user apparently banned as I can't see his profile either. Though you can read the Google cached version here: http://webcache.googleusercontent.com/search?q=cache:RO7AOsnHcWkJ:www.webhostingtalk.com/showthread.php%3Fp%3D9291666+&cd=1&hl=en&ct=clnk&gl=us&client=firefox-a

According to: http://www.custombuttonco.com/custom-button-co-blog/zopim-chat-security-breach/ , which was posted today, they were breached but there is no other source from what I can find online.

Anyhow, heads up.
 

Geek

Technolojesus
Verified Provider
If that's true, it marks the 4th or 5th time that's happened I think...

I was emailed the last time they were breached, not sure why I wasn't this time.

Figure I'm pretty well done with them if this turns out to be valid.
 

Hxxx

Active Member
Recently, we deployed a patch to fix performance issues for the system that powers advanced search capabilities in Zopim. That patch inadvertently led to Zopim account holders being able to access the chat records and transcripts of other accounts if they were to run an advanced search of account history. This vulnerability also permitted a limited export of records that included end user email addresses from certain Zopim accounts.
Really bad developing practices. Super disappointing. Looks like the patch went directly from the workstation of the developer to production.

Also somebody got fired.
 

MannDude

Just a dude
vpsBoard Founder
Moderator
Bahaha....

Wonder why WHT pulled the post?
It's possible they believed the link he posted in the thread was his own, I don't know. I'm posting it over there now, simply because it's important for customers/users of the service to know.
 

MartinD

Retired Staff
Verified Provider
Retired Staff
Steven's security list sent out an email about this earlier today I think.
 
Top
amuck-landowner