@treesmokah said:
Define low-cost, there are many great providers with custom non-WHMCS panels, actual security teams and competent developers, and its possible to get them for decent money.
When I see WHMCS my first thought is laziness, I value providers doing stuff on their own and not recycling shit everyone else uses that enables such "supply chain attacks".
Maybe you can name a few?
I can think of a few, but not that many.
In fact it doesn't necessarily bother me that a provider uses proprietary software that is fairly common in the industry.
Let's just say that their core business isn't necessarily developing software. It's necessarily better if they control the whole chain, if it's done well.
You need skills to do that properly. You're less of a vector for attacks because you're the only one using your software, but on the other hand your software is much less audited and so errors can just as easily creep in.
There is one thing that bothers me though. It's that the delay in notifying gives the impression that they wanted to sweep it under the carpet.
And that's unacceptable. That's why I have mixed feelings about it.
@Calypso said:
Yes, I can imagine that you have a priority to get the hacker out, and repair stuff, but on the other side of things: communicate with your users. I haven't seen anything. If a hacker has gained access to your systems, you should always keep your customers informed - that's even mandatory in a lot of countries.
So...I suppose the network status incident that we kept updated non-stop, and quoted by the OP even in this thread, didn't exist?
What is with people these days...making assumptions without any knowledge, and not even capable of reading.
Let me help you out:
The OP posted info from our network status information that was consistently updated with what status and steps were being taken regarding a ddos/hack attack our VPS platform was having. We literally posted tons of updates there as it was underway. At this point most of it consolidated and the update by update listing consolidated and/or removed. Clients were fully and non-stop informed here, and pointed to such with any support tickets as well.
Let me help you out:
My VPS was down for quite some time earlier this month: over 6 hours. I tried to reach your site: also unreachable. When finally I was able to reach your portal, the first thing I checked was network status. Nothing. Absolutely nothing. Cause for that? I don't know: could be that it wasn't updated (yet), could also be that website was restored from an old backup. But I know what I've seen: no network downtime reported in the network status.
Basically what you are trying to say is "you are wrong customer". No, I am not, I'm not stupid. OP can have that information from the website, yes. But my ticket was from before that time, and not a few hours, no a couple of days. A few days later (after this topic was opened) the ticket wat "answered" with a simple "Services restored" and some ping data. Yeah, can see that myself. Not a single word about what happened. The main reason I made the ticket was that it was not the first downtime: 28th of December over 7 hours, and during the days before average packet loss was over 30%. Not a word about those has come back in the ticket.
Also sending out a mail today to all(?) customers is a bit late don't you think when the incident was "late December". A bit late I think personally when personal information is involved in combination with a (what you say unrelated) quite large amount of unreachability of VPS. Especially when you have that many tickets, I'd say: first send a mail out to all your customers with what's going on, and mention the big pile of tickets so people can understand response times...
But no, you come here and changing words of a customer and saying that he's wrong. Way to go. I've never suggested that the downtime or hack didn't happen. I've just said that the communication about everything was lacking. And by only sending out a mail today to customers you're, in my opinion, comfirming that statement of me. What is it with hosting providers these days, they make assumptions and appear unable to read. O wait, that's what you accused me of... strange world...
@Brueggus said:
This just arrived. No message from LetBox so far.
I received this email from LetBox. Hum.
Notice of Cybersecurity Incident
Attn: O Great One -
We are writing to notify you of a recent event that may have impacted your personal information.
At this time, we have no indication of fraudulent use of your personal information as a result of this incident.
Nevertheless, we are notifying you out of an abundance of caution to explain the circumstances as we understand them.
What Happened
LetBox recently became aware in late December 2023 of a cybersecurity incident impacting its client/billing platform.
An individual(s) accessed LetBox LLC's client/billing system administrative areas without authorization, including gaining access via a 3rd party vendor module.
The individual(s) claimed to have downloaded customer data from LetBox's computer systems, then threatend to post and disclose the data on an Internet forum.
Upon being made initially aware of a potential breach, LetBox immediately began an investigation into the incident.
Although no data has been released that we have seen by this individual(s) as of this time, LetBox has determined the client/billing system was indeed breached.
What information was potentially accessed?
The compromised data would include client names, address information, phone numbers, email addresses, user names, and account/service passwords
LetBox does not store financial information on this platform, such as credit/debit card information, which would be stored directly with our 3rd party credit card processor.
LetBox does not have any more sensitive information about our client base such as financial information, social security numbers, ID numbers, drivers license information, etc...
What We Are Doing
We take the security of our customers’ data seriously, and after LetBox became aware of the event, we took immediate measures to investigate and remediate the incident.
We have implemented additional safeguards to improve security related to 3rd party software/modules, and the client/billing platform as a whole.
When LetBox was made aware of the potential breach, we immediately performed global password resets for all client accounts and the server/service passwords that we could.
We also updated all internal system access methods/connectivity.
We have also hired external security consultants to review the matter and assist as well.
Please be assured that we take data security and confidentiality very seriously.
Steps LetBox has taken to implement additional layers of security (not necessarily in this order):
Identified/removed the primary vulnerability associated with this incident
Global password resets for all users/systems
Update platform security settings and access credentials
Collaborated with cybersecurity specialists to review the situation
Reinstall clean system platform
Notified client base about the incident
Strengthen login credentials/methods and continue to enhance login protocols/procedures and other security measures
Continuing to monitor the situation and investigate this incident
Why did it take LetBox so long to notify me about this?
LetBox’s investigation is ongoing. As soon as LetBox learned that its environment had been accessed by an unauthorized party, LetBox immediately commenced the investigation, including working with third-party security consultants. System lockdowns were immediately implemented even before we could completely verify the breach. Simultaneously, LetBox was dealing with another security issue at the same time, including DDOS/hack attempts against our VPS service platform, and we were unsure how/if the two issues were related. It took some time to diagnose, and we have only recently concluded by our staff, external security consultants, and software vendors, that they were unrelated issues.
Do you know who accessed the information illegally?
No, the identity of the individual(s) responsible for this incident is still being investigated; however, they refer to themselves as "Scavenger" and the "whmcssec" team.
Is the stolen information being misused?
At this time, there is no evidence that your information has been misused.
LetBox has not received any reports of misuse of specific individual’s personal information as a result of this incident.
We understand that this same individual(s) have conducted systematic similar breaches recently of hundreds of other web hosting providers in the industry.
It is our understanding that the system breach was done to prove a point, and force hosting providers to make security policy/procedure changes.
Does this mean I am a victim of identity theft or identity fraud?
No. This means that some personal information is in the hands of unauthorized individual(s), and they could use it to commit identity theft or identity fraud.
If you believe you are the victim of identity theft or fraud, you should immediately report it to local law enforcement.
What You Can Do
There is no reason to believe that you need to take necessary action at this time regarding the personal contact information.
We do recommend again changing your login passwords to the client/billing interface, and to any server/system provided with your LetBox service, in case global resets did not complete such.
We also recommend implementing two-factor authentication (2FA) on your account, if not done so alrewady, which can be done at:
[redacted]
As a best practice, we recommend you remain vigilant and promptly report any suspicious activity, or suspected identity theft, to the proper law enforcement authorities and financial and banking service providers.
On behalf of LetBox, we apologize for this security breach and for any concern this may have caused.
We have subsequently taken, and continue to take, a number actions to ensure that this incident is thoroughly resolved, and to minimize the risk of a similar incident recurring
If you have any further questions, you are welcome to contact us by responding to this email notification.
Just a few from my head. Most providers I use/d, use custom panels.
It's not the same price range.
I'm not saying that it's not worth investing a little more.
But most of the providers mentioned don't / rarely make offers on LES / LET.
Thanks for the list though.
@remy said: But most of the providers mentioned don't / rarely make offers on LES / LET.
They do not cater to LowEndAudience which usually creates problems over funny amounts of money, and I respect that, not everyone has time to deal with LowEndMinds.
Many of the providers I listed cater to audience that needs resilience, no matter who hates you, they will host you and tell attackers to fuck off. There are not many providers with balls left, and many of listed ones certainly got them.
Mevspace in particular not only is resilient but also offers extremely nice prices on dedicated servers.
The same goes for Terrahost and their "entry" series, unmetered(no FUP) 1Gbps dedi for $40? I would take it any day, especially when they ignore DMCA and other funny "legal" threats and offer high capacity in-house ddos protection(which is extremely rare nowadays).
ml.cloud aka Media Land LLC, just google them Its as close to North Korea location as you gonna get, less than 2h by car.
So... I have an account on SmartHost. Inactive, for years, but there is still my PI there [just tested it by reset password - email arrived, didn't reset, didn't login].
I did not get any e-mail until now (it's like 7+ hours, kinda enough for mailing to go thru millions of e-mails) - did they send it only to active users?
@FrankZ do you have a service active (or recently?) on LETBOX? @Brueggus - same, what are you active (recent) service status for LB/SH?
Haven't bought a single service in VirMach Great Ryzen 2022 - 2023 Flash Sale.
Just got my notice today; pretty shameful conduct by a provider.
First there was no notification of the ddos attack; I had to open a ticket at the time and ask what is going on with the steal. Communication is easy and cheap. It would have taken five minutes to hammer out a notification to all affected clients when I was clear that it wasn't going to be a quick or easy resolution. But nothing happened.
So the real question, was it just an oversight, or was there hope that it would go unnoticed my most and get forgotten, or that the customer is not worthy or deserve to be notified of an attack that went on for over a week?
Secondly why did it take weeks and weeks for the provider "to do the right thing"? The allegation first arose weeks ago on LET. If there was any concern or respect of the clients, notification of the breach could have/should have been sent out ASAP.
Also: Is there actually a network status page on smarthost.net anywhere? I've never found one.
Got an email that says the following:
SmartHost LLC recently became aware in late December 2023 of a cybersecurity incident impacting its client/billing platform.
When SmartHost was made aware of the potential breach, we immediately performed global password resets for all client accounts and the server/service passwords that we could.
I just checked my password manager. I created the entry for @SMARTHOST late August/early September 2023, and have succesfully used that very password today to log into both the client area as well as the SolusVM panel.
Edit: all the communication from @SMARTHOST since that date are 1) related to invoice payment (invoice, reminder, payment confirmation) and 2) a reply to a ticket asking about downtime, getting a "there's ddos + hack attempt" in it. That information was not freely sent by @SMARTHOST but required me to send in a ticket myself.
Hence, there's no communication on email until today. The latest news on their own website is from late August 2023, talking about a new DC.
Also: Is there actually a network status page on smarthost.net anywhere? I've never found one.
Got an email that says the following:
SmartHost LLC recently became aware in late December 2023 of a cybersecurity incident impacting its client/billing platform.
When SmartHost was made aware of the potential breach, we immediately performed global password resets for all client accounts and the server/service passwords that we could.
I just checked my password manager. I created the entry for @SMARTHOST late August/early September 2023, and have succesfully used that very password today to log into both the client area as well as the SolusVM panel.
Edit: all the communication from @SMARTHOST since that date are 1) related to invoice payment (invoice, reminder, payment confirmation) and 2) a reply to a ticket asking about downtime, getting a "there's ddos + hack attempt" in it. That information was not freely sent by @SMARTHOST but required me to send in a ticket myself.
Hence, there's no communication on email until today. The latest news on their own website is from late August 2023, talking about a new DC.
I received a similar email from LetBox. Also similarly, I logged in to change my password after receiving the email, and I was able to log in with the previous password.
@remy said: I didn't intend to renew my services because of the lack of communication,now I'm hesitating.
If you are thinking about it, I'm sorry, but there is no hope for you.
I don't want to be mean, but after all of this shitshow, buying anything from them is the last thing I would be thinking of.
But you do, and that is exactly what you have been, and are still continuing on doing.
I was somewhat caught by surprise too when I discovered that I could not login to the smarthost control panel sometime back in late September. I had to do a password reset to regain access. I didn't recieve any spam mails though.
@remy said: I didn't intend to renew my services because of the lack of communication,now I'm hesitating.
If you are thinking about it, I'm sorry, but there is no hope for you.
I don't want to be mean, but after all of this shitshow, buying anything from them is the last thing I would be thinking of.
But you do, and that is exactly what you have been, and are still continuing on doing.
~ SMARTHOIST
Cry about it.
@cornercase said:
Since @SMARTHOST is feeling so talkative now: Maybe they can explain the leak of customer email addresses in late September:
@remy said: But most of the providers mentioned don't / rarely make offers on LES / LET.
They do not cater to LowEndAudience which usually creates problems over funny amounts of money, and I respect that, not everyone has time to deal with LowEndMinds.
Many of the providers I listed cater to audience that needs resilience, no matter who hates you, they will host you and tell attackers to fuck off. There are not many providers with balls left, and many of listed ones certainly got them.
Mevspace in particular not only is resilient but also offers extremely nice prices on dedicated servers.
The same goes for Terrahost and their "entry" series, unmetered(no FUP) 1Gbps dedi for $40? I would take it any day, especially when they ignore DMCA and other funny "legal" threats and offer high capacity in-house ddos protection(which is extremely rare nowadays).
ml.cloud aka Media Land LLC, just google them Its as close to North Korea location as you gonna get, less than 2h by car.
well LES can also tell providers to fuckoff, but there are to many mjj's around. I will cancel my Services with this Provider at the end of the billig periode.
Comments
So the hack was unrelated huh
Maybe you can name a few?
I can think of a few, but not that many.
In fact it doesn't necessarily bother me that a provider uses proprietary software that is fairly common in the industry.
Let's just say that their core business isn't necessarily developing software. It's necessarily better if they control the whole chain, if it's done well.
You need skills to do that properly. You're less of a vector for attacks because you're the only one using your software, but on the other hand your software is much less audited and so errors can just as easily creep in.
There is one thing that bothers me though. It's that the delay in notifying gives the impression that they wanted to sweep it under the carpet.
And that's unacceptable. That's why I have mixed feelings about it.
Let me help you out:
My VPS was down for quite some time earlier this month: over 6 hours. I tried to reach your site: also unreachable. When finally I was able to reach your portal, the first thing I checked was network status. Nothing. Absolutely nothing. Cause for that? I don't know: could be that it wasn't updated (yet), could also be that website was restored from an old backup. But I know what I've seen: no network downtime reported in the network status.
Basically what you are trying to say is "you are wrong customer". No, I am not, I'm not stupid. OP can have that information from the website, yes. But my ticket was from before that time, and not a few hours, no a couple of days. A few days later (after this topic was opened) the ticket wat "answered" with a simple "Services restored" and some ping data. Yeah, can see that myself. Not a single word about what happened. The main reason I made the ticket was that it was not the first downtime: 28th of December over 7 hours, and during the days before average packet loss was over 30%. Not a word about those has come back in the ticket.
Also sending out a mail today to all(?) customers is a bit late don't you think when the incident was "late December". A bit late I think personally when personal information is involved in combination with a (what you say unrelated) quite large amount of unreachability of VPS. Especially when you have that many tickets, I'd say: first send a mail out to all your customers with what's going on, and mention the big pile of tickets so people can understand response times...
But no, you come here and changing words of a customer and saying that he's wrong. Way to go. I've never suggested that the downtime or hack didn't happen. I've just said that the communication about everything was lacking. And by only sending out a mail today to customers you're, in my opinion, comfirming that statement of me. What is it with hosting providers these days, they make assumptions and appear unable to read. O wait, that's what you accused me of... strange world...
https://terrahost.com/
https://nicevps.net/
https://hosteam.pl/
https://4vps.su/
https://ml.cloud/
https://serveroffer.lt/
https://mevspace.com/
https://evoluso.com/
https://privatealps.net/
https://datawagon.com/ (never used, I do not endorse them)
Just a few from my head. Most providers I use/d, use custom panels.
v6node.com too. It's one of the best panels I've used. I really liked the UI.
The Ultimate Speedtest Script | Get Instant Alerts on new LES/LET deals | Cheap VPS Deals | VirMach Flash Sales Notifier
FREE KVM VPS - FreeVPS.org | FREE LXC VPS - MicroLXC
I received this email from LetBox. Hum.
Notice of Cybersecurity Incident
Attn: O Great One -
We are writing to notify you of a recent event that may have impacted your personal information.
At this time, we have no indication of fraudulent use of your personal information as a result of this incident.
Nevertheless, we are notifying you out of an abundance of caution to explain the circumstances as we understand them.
What Happened
LetBox recently became aware in late December 2023 of a cybersecurity incident impacting its client/billing platform.
An individual(s) accessed LetBox LLC's client/billing system administrative areas without authorization, including gaining access via a 3rd party vendor module.
The individual(s) claimed to have downloaded customer data from LetBox's computer systems, then threatend to post and disclose the data on an Internet forum.
Upon being made initially aware of a potential breach, LetBox immediately began an investigation into the incident.
Although no data has been released that we have seen by this individual(s) as of this time, LetBox has determined the client/billing system was indeed breached.
What information was potentially accessed?
The compromised data would include client names, address information, phone numbers, email addresses, user names, and account/service passwords
LetBox does not store financial information on this platform, such as credit/debit card information, which would be stored directly with our 3rd party credit card processor.
LetBox does not have any more sensitive information about our client base such as financial information, social security numbers, ID numbers, drivers license information, etc...
What We Are Doing
We take the security of our customers’ data seriously, and after LetBox became aware of the event, we took immediate measures to investigate and remediate the incident.
We have implemented additional safeguards to improve security related to 3rd party software/modules, and the client/billing platform as a whole.
When LetBox was made aware of the potential breach, we immediately performed global password resets for all client accounts and the server/service passwords that we could.
We also updated all internal system access methods/connectivity.
We have also hired external security consultants to review the matter and assist as well.
Please be assured that we take data security and confidentiality very seriously.
Steps LetBox has taken to implement additional layers of security (not necessarily in this order):
Identified/removed the primary vulnerability associated with this incident
Global password resets for all users/systems
Update platform security settings and access credentials
Collaborated with cybersecurity specialists to review the situation
Reinstall clean system platform
Notified client base about the incident
Strengthen login credentials/methods and continue to enhance login protocols/procedures and other security measures
Continuing to monitor the situation and investigate this incident
Why did it take LetBox so long to notify me about this?
LetBox’s investigation is ongoing. As soon as LetBox learned that its environment had been accessed by an unauthorized party, LetBox immediately commenced the investigation, including working with third-party security consultants. System lockdowns were immediately implemented even before we could completely verify the breach. Simultaneously, LetBox was dealing with another security issue at the same time, including DDOS/hack attempts against our VPS service platform, and we were unsure how/if the two issues were related. It took some time to diagnose, and we have only recently concluded by our staff, external security consultants, and software vendors, that they were unrelated issues.
Do you know who accessed the information illegally?
No, the identity of the individual(s) responsible for this incident is still being investigated; however, they refer to themselves as "Scavenger" and the "whmcssec" team.
Is the stolen information being misused?
At this time, there is no evidence that your information has been misused.
LetBox has not received any reports of misuse of specific individual’s personal information as a result of this incident.
We understand that this same individual(s) have conducted systematic similar breaches recently of hundreds of other web hosting providers in the industry.
It is our understanding that the system breach was done to prove a point, and force hosting providers to make security policy/procedure changes.
Does this mean I am a victim of identity theft or identity fraud?
No. This means that some personal information is in the hands of unauthorized individual(s), and they could use it to commit identity theft or identity fraud.
If you believe you are the victim of identity theft or fraud, you should immediately report it to local law enforcement.
What You Can Do
There is no reason to believe that you need to take necessary action at this time regarding the personal contact information.
We do recommend again changing your login passwords to the client/billing interface, and to any server/system provided with your LetBox service, in case global resets did not complete such.
We also recommend implementing two-factor authentication (2FA) on your account, if not done so alrewady, which can be done at:
[redacted]
As a best practice, we recommend you remain vigilant and promptly report any suspicious activity, or suspected identity theft, to the proper law enforcement authorities and financial and banking service providers.
On behalf of LetBox, we apologize for this security breach and for any concern this may have caused.
We have subsequently taken, and continue to take, a number actions to ensure that this incident is thoroughly resolved, and to minimize the risk of a similar incident recurring
If you have any further questions, you are welcome to contact us by responding to this email notification.
LetBox Limited
Henderson, NV USA
[redacted]
So now finally an email gets sent out. Slow as snails
It's not the same price range.
I'm not saying that it's not worth investing a little more.
But most of the providers mentioned don't / rarely make offers on LES / LET.
Thanks for the list though.
They do not cater to LowEndAudience which usually creates problems over funny amounts of money, and I respect that, not everyone has time to deal with LowEndMinds.
Many of the providers I listed cater to audience that needs resilience, no matter who hates you, they will host you and tell attackers to fuck off. There are not many providers with balls left, and many of listed ones certainly got them.
Mevspace in particular not only is resilient but also offers extremely nice prices on dedicated servers.
The same goes for Terrahost and their "entry" series, unmetered(no FUP) 1Gbps dedi for $40? I would take it any day, especially when they ignore DMCA and other funny "legal" threats and offer high capacity in-house ddos protection(which is extremely rare nowadays).
ml.cloud aka Media Land LLC, just google them
Its as close to North Korea location as you gonna get, less than 2h by car.
So... I have an account on SmartHost. Inactive, for years, but there is still my PI there [just tested it by reset password - email arrived, didn't reset, didn't login].
I did not get any e-mail until now (it's like 7+ hours, kinda enough for mailing to go thru millions of e-mails) - did they send it only to active users?
@FrankZ do you have a service active (or recently?) on LETBOX?
@Brueggus - same, what are you active (recent) service status for LB/SH?
Haven't bought a single service in VirMach Great Ryzen 2022 - 2023 Flash Sale.
I was a client from March 2014 to Dec 2020. I do not have any active service with LetBox currently.
Since @SMARTHOST is feeling so talkative now: Maybe they can explain the leak of customer email addresses in late September:
https://lowendspirit.com/discussion/comment/151050/#Comment_151050
Was this a third incident?
Also: Is there actually a network status page on smarthost.net anywhere? I've never found one.
I have active services with both, unfortunately.
dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers • Need a free NAT LXC? -> https://microlxc.net/
Same. I got emails from both.
Just got my notice today; pretty shameful conduct by a provider.
First there was no notification of the ddos attack; I had to open a ticket at the time and ask what is going on with the steal. Communication is easy and cheap. It would have taken five minutes to hammer out a notification to all affected clients when I was clear that it wasn't going to be a quick or easy resolution. But nothing happened.
So the real question, was it just an oversight, or was there hope that it would go unnoticed my most and get forgotten, or that the customer is not worthy or deserve to be notified of an attack that went on for over a week?
Secondly why did it take weeks and weeks for the provider "to do the right thing"? The allegation first arose weeks ago on LET. If there was any concern or respect of the clients, notification of the breach could have/should have been sent out ASAP.
Got an email that says the following:
I just checked my password manager. I created the entry for @SMARTHOST late August/early September 2023, and have succesfully used that very password today to log into both the client area as well as the SolusVM panel.
Edit: all the communication from @SMARTHOST since that date are 1) related to invoice payment (invoice, reminder, payment confirmation) and 2) a reply to a ticket asking about downtime, getting a "there's ddos + hack attempt" in it. That information was not freely sent by @SMARTHOST but required me to send in a ticket myself.
Hence, there's no communication on email until today. The latest news on their own website is from late August 2023, talking about a new DC.
Hey teamacc. You're a dick. (c) Jon Biloh, 2020.
I received a similar email from LetBox. Also similarly, I logged in to change my password after receiving the email, and I was able to log in with the previous password.
LetBox notices sent as well at same time.
Seems to still be processing thru the external email provider that brand uses though.
~ SMARTHOST
SmartHost™ - Intelligent Hosting! - Multiple Locations - US/EU! - Join our Resale Program
https://www.smarthost.net - sales@smarthost.net - Ultra-Fast NVME SSD KVM VPS - $2.95/month!
But you do, and that is exactly what you have been, and are still continuing on doing.
~ SMARTHOIST
SmartHost™ - Intelligent Hosting! - Multiple Locations - US/EU! - Join our Resale Program
https://www.smarthost.net - sales@smarthost.net - Ultra-Fast NVME SSD KVM VPS - $2.95/month!
I was somewhat caught by surprise too when I discovered that I could not login to the smarthost control panel sometime back in late September. I had to do a password reset to regain access. I didn't recieve any spam mails though.
Cry about it.
Lol, I also heard unverified rumors they got breached 2 years ago.
Still no e-mail from SMARTHOST, must be a big mailling.
Haven't bought a single service in VirMach Great Ryzen 2022 - 2023 Flash Sale.
It seems.
I got the email from Letbox 24 hours ago and from Smarthost 7-8 hours ago.
well LES can also tell providers to fuckoff, but there are to many mjj's around. I will cancel my Services with this Provider at the end of the billig periode.