Security Advisory and Patch from WHMCS For 7.3, 7.4 and 7.5

Make sure all providers and resellers using WHMCS have patched your WHMCS installed due to below security advisory for WHMCS:

================================================
WHMCS Security Patch Released for 7.3, 7.4 and 7.5
https://blog.whmcs.com/133497/security-patch-released-for-73-74-and-75
================================================

Four potential security issues have been identified in WHMCS 7.5 and earlier.
It is recommended that you apply this patch as soon as possible.

The issues resolved include:
– Project permissions within the Project Management addon
– Potential XSS on admin homepage
– Improper client password reset logic
– Improper admin access to remote servers via WHMCS Connect

You can apply this patch using the Automatic Updater.
The Auto-Updater allows you to apply the patch to your current version,
or update to the latest available version (7.5.2) of WHMCS.
Learn more at https://docs.whmcs.com/Automatic_Updater#Configuring_Your_Update_Settings

Alternatively, you can download the patch for your version at
https://download.whmcs.com/#patch

To install the patch:

1) Download the appropriate files for your version of WHMCS
2) Upload all files found within the zip file to the root WHMCS directory
overwriting any existing files

If you are using WHMCS 7.2 or earlier, you should upgrade to WHMCS 7.5.2.

Respective Release Notes:
7.3: https://docs.whmcs.com/Version_7.3.1_Release_Notes
7.4: https://docs.whmcs.com/Version_7.4.3_Release_Notes
7.5: https://docs.whmcs.com/Version_7.5.2_Release_Notes

================================================

 

If you are a hosteons.com client and need help just submit a ticket from our website we will help you with it

Google Chrome Update 68 SSL Warning of Secure and Non-Secure Websites – Get Free SSL Installation with Hosteons.com

Google will be updating their browser Chrome to version 68 this July, once this browser update is released if your website does not have a SSL Certificate your website will show as non-secure website to all the visitors using Chrome Browser 68 which can lead to loss of trust and good will for your website, does not matter whether it’s a wordpress blog or an e-commerce portal, if you don’t have SSL enabled in your website you are going to loose a lot of visitors and your bounce rate will also increase and eventually your website will even start loosing ranking in Google and various search engines.

We at Hosteons.com are offering free SSL certificate along with installation of SSL certificate with all our web hosting packages, you can enable SSL directly from your cPanel account or just submit a ticket to do it for you. So switch your website to hostEONS.com before it’s too late. We have all kind of web hosting packages starting at just $1 to unlimited web hosting packages. All our Web hosting packages comes with following features:

  1. cPanel
  2. Softaculous (one click script installer for scripts like wordpress, forum software etc…)
  3. Free SSL Certificate
  4. Free IPv6 along with standard IPv4, so that your site is future proof
  5. Instant activation
  6. Mysql Database
  7. Multiple PHP Version available
  8. POP3 and IMAP email access
  9. Webmail
  10. Many more features

You can order it from https://hosteons.com/web_hosting.php

For any queries please submit a support ticket from https://my.hosteons.com

 

Stay away from AMD EPYC based VPS Providers

Some german researches have found a flaw in the AMD EPYC CPU architecture and were able to read all data of VPS hosted with AMD EPYC based CPU, and it seems currently there is no patch for it so it’s best to stay away from it for now, more information is available at:

https://www.techrepublic.com/article/encryption-of-amd-epyc-vms-can-be-broken-researchers-prove/

 

AMD responds to security flaws in its EPYC virtual machine encryption

 

We at Hosteons are not using AMD EPYC CPU, we are using Dual XEONS for VPS Hosting

Benefits of KVM VPS over other virtualisation technology

1. Dedicated Resources: KVM VPS are not like shared servers or other types of virtualisation e.g. OpenVZ where resources are shared among users, with KVM VPS you get dedicated resources as it’s not possible to oversell resources with KVM Virtualisation. If you have a KVM VPS from hostEONS.com you can be sure that you are getting the exact same amount of resources as you ordered. With OpenVZ it’s very easy to oversell all resources on the server but not with KVM.

2. Free from neighbourhood troubles: If you are using KVM VPS from hosteons.com you need not worry about bad scripts or softwares being run by other users on the same server because with KVM since all VPS runs on their own dedicated resources, any abusive activity by another VPS user won’t affect your VPS. Since you have full control over your VPS you can keep your VPS updated and secure and need not worry even if your neighbourhood VPS users are updated/secure or not.

3. Dedicated IP for mail and other activities: Hosteons VPS comes with dedicated IP with full RDNS control hence you need not worry about other VPS users spoiling IP reputation, and since you get RDNS control you can be sure that your mail will be delivered to the inbox of the recipient and won’t get bounced or going to junk mail.

4. Quick Reboot and Reinstalls: Hosteons KVM VPS comes with SolusVM control panel which gives complete control for Reboot, Reinstalls as well as VNC access

Credit Card data security at hosteons.com

PCI Compliance

We don’t store any credit card or debit card details in our billing system, we are using stripe as our payment processor.

Once the client makes payment on our website, the card details are sent to Stripe over SSL and in return Stripe’s secure servers send our billing system a token which is stored in our billing system, we just store this token and never store any card details in our system (we do store last 4 digits of credit card) so that client can identify which card is being used to make payments.

Whenever an invoice is due and if you paid with credit card earlier, we just use this token to charge your card again.

Since we don’t store credit card details in our system we don’t need PCI Compliance and you can use your credit card/debit card without worrying about any security breaches or misuse of your credit card.

for any further queries feel free to submit a ticket in client portal at https://my.hosteons.com

Alipay now accepted for all our hosting services

we accept alipay

We have got approval from Alipay and we are now able to accept payments via Alipay which is very popular in China.

Our VPS servers are already on China optimised network and now we can even accept payments via Alipay.

There is a restriction by Alipay which allows us to accept payments only in currency local to our country, due to which we will be accepting payments via Alipay in SGD (Singapore Dollar) and not USD. There is no change for clients as all clients will placing order in USD but at the time of payment our system will automatically convert the payment amount SGD from USD

Reset root password when stuck at FSCK

Stuck at FSCK but your root password is not working ?

Here is a short tutorial on how to reset root password on a  Linux VPS or Dedicated Server 

  1. First login to your VPS control panel and use VNC to access the VPS Console and if it’s a Dedicated server either use the IPMI or use a KVM to go to console of your server.
  2. Now let your system boot and press spare on grub menu to pause the system from booting and going at fsck prompt
  3. Now select the last working kernel and press ‘e’
  4. Now Go to the link similar to below and press ‘e’:    “kernel /vmlinuz-x.x.x.x root=UUID.x.x.x.x ro rhgb quiet”
  5. Delete ‘ro’ from the line and append ‘init= /bin/bash’ for CentOS or ‘init= /bin/sh’ for Debian
  6. Press ‘Enter’ or ‘Return” key to save and the press ‘b’ to boot into single user mode
  7. Now the system should directly take you to your single user mode shell. Now type below command to mount the / file system in read write: mount -o remount rw /
  8. Once / File system is mounted, you can then change the root password with “passwd” command
  9. Now you can again reboot your system and run fsck using the above root password

 

Instant Dedicated Servers now available

instant dedicated server

Instant Dedicated Servers now available only at hosteons.com

We are offering instant provisioning of dedicated servers across two locations – USA and India

Thes servers are setup and delivered instantly upon payment without human intervention.

These servers comes with CentOS 7 64 preinstalled and even cPanel is available as an add-on, please note if you order server with cPanel then it will require some additional time to install cPanel.

These servers are are really helpful when you need a server urgently as most providers require at least 24 hours to deliver the server, but our instant dedicated servers are preinstalled and pre-configured and ready to be delivered.

For any queries please submit a ticket from our website https://hosteons.com