Security Advisory – HostBill versions 4.x

Started by Lawrence, June 11, 2013, 04:05:46 AM

Lawrence

There's been a security advisory for HostBill versions 4.x. This applies for anyone under the 4.x branch.

If you have the auto patcher, use it. If you'd rather update manually, continue reading.

You can download the security patch here.
- https://hostbillapp.com/clientarea/patches/hostbill_patch4.6.4_4347.zip

When you've downloaded the security patch, extract the contents into the main HostBill directory.
Skype: sociallarry | AIM: [email]larry.aim@aim.com[/email] | Forum Rules & Information

These forums are hosted by me with no intentions to ever monetize them. These forums are here solely for the benfit of the HostBill community.

CBlade


UCG_Keith

Hi Lawrence,

Curious about the security patch; where is the CVE about the issue?  Was it published by HostBill? 

Lawrence

Skype: sociallarry | AIM: [email]larry.aim@aim.com[/email] | Forum Rules & Information

These forums are hosted by me with no intentions to ever monetize them. These forums are here solely for the benfit of the HostBill community.

nldaniel

#4
Looks like we might be in for some rough waters;

http://www.webhostingtalk.com/showthread.php?t=1277173
http://vpsboard.com/topic/786-hostbill-source-code-released-and-0-day-exploits-found/?p=11769

I'm still downloading to see what actually could be vulnerable; regardless we've still taken measures and disabled public hostbill in light of current SolusVM hacks.

Edit: Looks like just the front index.php got decoded; nothing backing up the "exploits found" claim

Patrick

#5
Quote from: nldaniel on June 19, 2013, 12:55:38 AM
Looks like we might be in for some rough waters;

http://www.webhostingtalk.com/showthread.php?t=1277173
http://vpsboard.com/topic/786-hostbill-source-code-released-and-0-day-exploits-found/?p=11769

I'm still downloading to see what actually could be vulnerable; regardless we've still taken measures and disabled public hostbill in light of current SolusVM hacks.


Looking through the "source" files and a lot of it is still encrypted.  So far almost every file i've looked at.  This almost appears to be a false claim.  I cannot take this seriously until i see more.
Patrick - Forum Rules
Insanity: doing the same thing over and over again and expecting different results. - Albert Einstein

cloudhopping

I agree -  The real question however is -   If someone decoded 1 file -
can they do more.

It could be a teaser - just in case I am keeping my ears to the ground in a few of the communities we all know exist for this kind of stuff - just in case.


TommyK


Patrick

The one file was decoded by dezender.  It is a legitimate decoder web site that charges about $5 a file.  So someone paid to decode the 1 file and create a "scare" is my opinion of it at this moment in time.  Not saying this isn't something to be taken lightly but right now there is absolutely no evidence that i can see to the contrary
Patrick - Forum Rules
Insanity: doing the same thing over and over again and expecting different results. - Albert Einstein

cloudhopping

#9
with places like  Linked removed for legal reasons

it is only a matter of time before someone writes a simple script to shoot a command and decrypt each with $0 invested.

I do not place the blame for this on Kris - ioncube needs to step up the game and ensure that these tools do not work once they are made and allow recryption (is that a word)  if their crypt gets wanked...


CBlade

Ok, they decoded it, what version? Now this mean we will see a Open Hostbill project under GPL?

joel

Hi,

Is there any way to find the host bill installations on a cpanel server?

Enterprisevpssolutions

You have to be a little more specific on the question. Are you talking about looking for the install folder? http://wiki.hostbillapp.com/index.php?title=Installation. You need to start another post if you need help.
Enterprise Vps Solutions (VPS) - Cloud Solutions, Shared hosting, VPS , and more, Fast Dedicated Servers. Great ssl prices SSL Certs, Follow us on Twitter. Sales Question? Contact us! Send us a Request Tampa , Florida Hivelocity Datacenter

joel

Hello,

Thanks for your updates. My intention was to look for all hostbill installations under the accounts in a cPanel server and patch the new version. Need your suggestion to find out the best way to proceed.


joel