*** PH_ (6d6a6a7b@gateway/web/freenode/ip.109.106.106.123) has joined #wikid | 10:31 | |
PH_ | hi | 10:31 |
---|---|---|
*** PH_ has parted #wikid (None) | 10:32 | |
*** nowen (~nowen@adsl-74-176-163-56.asm.bellsouth.net) has joined #wikid | 12:10 | |
*** laszlof (~laszlof@wookie.tvog.net) has joined #wikid | 14:55 | |
laszlof | thanks for the email nick :) | 15:02 |
nowen | hehe, I should have known you're were ahead of me on it | 15:03 |
laszlof | I was actually on the phone with Matt (the owner of WHMCS) when it all happened | 15:04 |
nowen | ouchie | 15:04 |
nowen | you sell him on some 2FA? ;)\ | 15:04 |
laszlof | working on it, though that wasnt really the issue here | 15:04 |
nowen | (that's a typo, not some new emoticon) | 15:04 |
laszlof | he had everything hosted on 1 box, the hackers use social engineering to get the hosting company to give up the servers password | 15:05 |
laszlof | and the box used cpanel :/ | 15:05 |
nowen | ahh - but if he used 2FA on the server they wouldn't have a had a password to give, right? | 15:06 |
laszlof | yeah, but you cant do that with cpanel | 15:06 |
nowen | ahh - that's right | 15:06 |
laszlof | im trying to get him to get rid of cpanel all together | 15:06 |
laszlof | they dont need it | 15:06 |
nowen | what are you proposing instead? | 15:06 |
laszlof | a minimal LAMP install on several servers, separating various business items on segregated networks | 15:07 |
laszlof | i.e., a database server, a web server, a logging server, possibly a firewalled access server to manage them | 15:08 |
laszlof | whats scary is how much money they're making, and not having this done already | 15:08 |
laszlof | numbers being thrown around based on the database dump the hacker got is somewhere to the tune of $500K/month | 15:08 |
nowen | well, making money tends to be relaxing. | 15:09 |
nowen | not that i would know | 15:09 |
laszlof | haha | 15:09 |
laszlof | tell me about it | 15:09 |
nowen | $500k/mo is a lot of relaxation | 15:11 |
laszlof | yeah.. | 15:11 |
laszlof | that number is probably over-estimated.. someone took the number of active clients listed and multiplied it by $7/month | 15:11 |
laszlof | which is the minimum monthly charge for WHMCS | 15:12 |
laszlof | but some people have multiple licenses, some have owned licenses. etc | 15:12 |
*** nowen has quit (Quit: Leaving.) | 23:03 |
Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!