hack whmcs v7

saadatidust

New member
Apr 25, 2021
24
0
1
Is it possible that there is another malicious script on the host? Or are the same files that Antivarvel found on my host only active scripts?
 

saadatidust

New member
Apr 25, 2021
24
0
1
I see this code in the .htaccess file. Is this code public code or malicious code?
Code:
# php -- BEGIN cPanel-generated handler, do not edit
# Set the “ea-php74” package as the default “PHP” programming language.
<IfModule mime_module>
  AddHandler application/x-httpd-ea-php74 .php .php7 .phtml
</IfModule>
# php -- END cPanel-generated handler, do not edit
 

saadatidust

New member
Apr 25, 2021
24
0
1
Is it normal or unusual for these files to start with a dot?
How to search and delete all these types of files that start with a dot? file.jpg
 

saadatidust

New member
Apr 25, 2021
24
0
1
I found a file in the host called adminer.php, the execution of which gives us the username and password information to visit, and he can easily change it.
The question is, how did he manage to upload this file to our hosts?
The desired file is found in the directory of one of the WordPress plugins. But can we upload the effects of that file to everyone on the host? See the directories?
How could he
 
  • Sad
Reactions: d3v1l

d3v1l

Well-known member
Banned User
Dec 24, 2020
362
697
93
22
India
d3v1l.co
I found a file in the host called adminer.php, the execution of which gives us the username and password information to visit, and he can easily change it.
The question is, how did he manage to upload this file to our hosts?
The desired file is found in the directory of one of the WordPress plugins. But can we upload the effects of that file to everyone on the host? See the directories?
How could he
Just do one thing update whmcs to latest version.
 

iegyi

New member
Nov 22, 2019
4
0
1
We have a large web hosting company, We can migrate all of your websites for free also we will secure your whmcs installation 100% , We are in this industry since 2004
 

thambyz

Active member
Mar 18, 2021
103
41
28
If you are using WordPress in same account, might be first WordPress got compromised and then from that they got into WHMCS. If you are using both WordPress and WHMCS in same account, you need to check both for any malicious files. I suggest using WHMCS in a subdomain with separate account.

WordPress is easy to get compromised (compared to WHMCS). When hacker got into your account from WordPress, they can see all files including WHMCS, they can access to WHMCS DB using details from configuration file and do whatever they want.
 

About us

  • Our community has been around for many years and pride ourselves on offering unbiased, critical discussion among people of all different backgrounds. We are working every day to make sure our community is one of the best.

Quick Navigation

User Menu