Another forum got hacked and credit card information stolen.

Status
Not open for further replies.

Safa

🗣️ Loud Newcomer
Jan 26, 2009
236
0
36
For some days ago another forum got hacked and this time it was one of the major ones, the problem wasn't the forum itself, god, they have still troubles to rebuild it, however, no the trouble is, that all the credit card information from their paying users was STORED on the servers.


It is against PCI regulations to store any credit card information on the server if you are not PCI compliant itself, it don't matter if the hosting company is compliant, no, the company and their servers need to be PCI complian.


So, it looks like who ever is the technical chief for webhostingtalk.com is an idiot.


The recent hack apparently revealed that iNet (the company that owns webhostingtalk.com) was storing unencrypted credit card details, including CVV codes, in their database.... which was just recently hacked... and stolen... and they didn't even know about it until the hacker told them.


The lesson?


Everyone gets hacked. That isn't the question. Yes, I feel bad for iNet being hacked. It's sucky, but really.. that's not the issue nor is it the lesson here.


The lesson...


Don't be an idiot.


1. If you must store credit card details, then encrypt them before storing them. Only an idiot would store their customer's unencrypted credit card details in a database.


2. DO NOT STORE CVV DETAILS. This is against visa/mc regulations, and is even against the law in some countries. CVV codes may not be used for anything except the transaction of the moment. If you store the cvv code anywhere, then you are not only an idiot, but you are very likely to get banned from ever having a merchant account again.

Toggle signature
Anybody running beats anybody walking, and anybody walking beats anybody sitting.
 
Normally we do not allow to post urls to other forums at all, but in this case it is okay, you have a good point here, and shame on this forum to store the CC information and not be secured.

Toggle signature

Latest Video Interviews, Offshore Company Resources, Payment Processing Tips & Tricks, Articles and Anonymity Hints only a click away!
Support the Freedom of Speech of our Community

Disclaimer: Nothing I say should be taken as tax, legal or financial advice. Anything I say is for general informational purposes only. Always seek independent professional advice.
 
Thank you Admin, I thought it was interisting reading for all 🙂

Toggle signature
Anybody running beats anybody walking, and anybody walking beats anybody sitting.
 
Thank you for sharing the information, nice reading and hell, people should get their servers secured and don't store any credit card information at all.
 
Status
Not open for further replies.

JohnnyDoe.is is an uncensored discussion forum
focused on free speech,
independent thinking, and controversial ideas.
Everyone is responsible for their own words.

Quick Navigation

User Menu