Paycom Clients Change your FTP Passwords!!!

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • aico
    Moo Moo Cow
    • Mar 2004
    • 14748

    #1

    Paycom Clients Change your FTP Passwords!!!

    I have just been informed by my server company (reflected.net) that they have found the source of how I, and other clients of theirs, that apparently Paycom has been hacked and they got my FTP passwords from them, which is how they fucked with my and many other peoples sites lately.

    Discuss...
  • Pron Don
    Internet Entrepeneur
    • Jun 2006
    • 571

    #2
    very very shitty
    Sig currently being donated to science.

    don of pron at gmail dot com

    Comment

    • artman
      Confirmed User
      • Nov 2005
      • 770

      #3
      that's fucked

      Comment

      • aico
        Moo Moo Cow
        • Mar 2004
        • 14748

        #4
        *how I, and several of their other clients, got hacked (sorry got sidetracked mid-sentence).

        Comment

        • aico
          Moo Moo Cow
          • Mar 2004
          • 14748

          #5
          Ok, I may have jumped the gun, they are not sure it was Paycom, they are still looking into it... my bad. Will let you know more as I do.

          Comment

          • marketsmart
            HOMICIDAL TROLL KILLER
            • Dec 2004
            • 20419

            #6
            sounds to me like your host needs to lock down your server... if its just ftp issues have them make ftp restricted to ip's.....

            Comment

            • Phil21
              Confirmed User
              • May 2001
              • 993

              #7
              Just thought I'd interject here..

              We've been tracking an issue a few other hosts have been looking into over the past weeks or so. The common thread essentially is a one-shot successful login to a valid FTP account (e.g. no password guessing, etc.), and adding of some malicious code containing an iframe to various html and php pages.

              Currently, at least with our customer base, it appears an external third party may have had a password database compromised. Paycom is just one of a few sources this data could be from, and in Aiko's case that was one biller used. Some unfortunate language was used by an technician in the ticket response, which made it look like we were certain of the source.

              The other possibility is a backdoor of some sort (like spyware) going around that may look into FTP software saved passwords.

              Anyways, as we know more we will dispense info on to our clients. A good practice for most everyone would be to change any FTP or other account passwords you have given out to any third parties immediately. Also as someone mentioned, if you have the ability to know where you'll always be FTP'ing from, firewalling off everything else provides a good level of protection from leaks such as these in the future.

              -Phil
              Quality affordable hosting.

              Comment

              • WiredGuy
                Pounding Googlebot
                • Aug 2002
                • 34516

                #8
                I have a feeling if the source was the processor, there would be a lot more clients who were compomised.
                WG
                I play with Google.

                Comment

                • CaptainHowdy
                  Too lazy to set a custom title
                  • Dec 2004
                  • 94125

                  #9
                  Holy crappers, that's bad...

                  Comment

                  • Choppa
                    Confirmed User
                    • Mar 2006
                    • 4079

                    #10
                    hmmmm not good at all
                    SexyAds: 10 years in business and still going strong. Become an affiliate today!




                    Choppas ICQ: 283 090 747 Want to know more? [email protected]

                    Comment

                    • gooddomains
                      Too lazy to set a custom title
                      • Jul 2003
                      • 10127

                      #11
                      that's not good news

                      Comment

                      • V_RocKs
                        Damn Right I Kiss Ass!
                        • Nov 2003
                        • 32451

                        #12
                        Doesn't mean Paycom was hacked... Could mean you are leaving the info open or the FTP software itself is hackable.

                        Comment

                        Working...