LES Members Respond to FlorinMarian Exposing IHostArt Panel Issues
Hello everyone we informed recently about a data breach of our main website (ihostart.com data base)
we would like to inform you that the data on the VPS was NOT AFFECTED, only the database of the website ihostart.com, the following objects were compromised
Email address
Tickets requests/views
We recomanded for all customers ASAP , to change VPS password (as a precautionary measure) , we leave here coming soon more updates about this , in same time , i'm want inform , no one knew about this security breach, only after a user posted on LET, and we will take all legal measures for this
We leave in next hours more details about this situation

Comments
We send coming soon to all emails about this , for now we back to put website online
Just tell the truth ...
The bug was made public by a competing company named hazi.ro managed by @FlorinMarian ...
Calin borked web server config and for unknown amount of time visitors could download raw .php files. Whmcs config file also was accessed raw.
@FlorinMarian exposed redacted config file publicaly on LET to defame calin. A scum move.
Data breach happened at 8:25 PM - 1/18/2024 (bucharest time)
We shutdown all our web servers at 8:37 - 1/18/2024 (bucharest time)
@everyone For now we confirmed just config.file and our data base password start expose , we confirm coming soon if anybody download main data base
Could database be accessed remotely?
>
Hello no ,all work at localhost
I'm a huge proponent of responsible disclosure, and that thread on LET is not even close to being responsible.
It's clear that thread was created with the intent to harm @Calin/IHostArt, I would genuinely be surprised if it didn't result in a ban.
Swiftnode LLC − Baremetal | Colocation | Cloud | DDoS Mitigation
Established 2014 − 24/7/365 Support − 1000+ Customers Served
Yeah, Florin is a real piece of crap for that. Also, Calin, buy a legitimate WHMCS license and don't use a nulled one...
[ IncogNET LLC ] - Since 2020
[ The Internet Speech & Privacy Company ]
Lord is this true.
ExtraVM - KVM NVMe VPS in USA, EU, APAC -|- RackColo - Find Colo
Wow!
Calin: "hi, we fix license next week"
Florin: "you are an idiot suggesting me to pay $60 per month for some license when my clients pay me peanuts"
Why?
@everyone After we investigate more attented this breach we confirmed emails or phones or tickets not exposed , just our password of config.php from WHMCS
AGAIN , as a precautionary measure we recommend you to change the VPS password
At the same time, we plan to migrate from WHMCS to blesta or another billing panel
We don't have for now a ETA when website back online
More Answers/Questions (Q&A)
Question: Data base it's possible accesed outside from VPS network?
Anwser: NO , we usage all on localhost
Question: Any customer from ihostart network possible try to login on web panel to accesed data base?
Answer: NO , we usage separed provider for our main website (ihostart.com / panel.ihostart.com)
Yes, the screenshot FlorinMarian posted of Calin's config file showed the first part of a shared license key,
Maybe you two should take a month off les and focus on drama at ogf.
ihostart.com shows legit on whmcs license checker though
Hey teamacc. You're a dick. (c) Jon Biloh, 2020.
From: https://lowendtalk.com/discussion/comment/3892511/#Comment_3892511
Maybe not nulled. Maybe nulled.
[ IncogNET LLC ] - Since 2020
[ The Internet Speech & Privacy Company ]
It didn't on the first checks after it was revealed on LET that it was a shared license.
I would hope that publicly exposing an exploit that could potentially leak customer data is bannable on LES as well.. it would be different if the issue was raised to Calin first and no measures were taken but the issue was never raised privately.
The provider tag was suspended pending review when this came to my attention. A final decision will be made regarding this after the rest of the LES staff has weighed in.
As long as they do not break the rules here at LES, I can't see how it would be justifiable to ban a member for things that they do elsewhere. As an example some members that are upstanding citizens here have been banned for actions taken at the OGF.
Devil's advocate, if a vendor deadpooled on OGF and a bunch of people lost money but he never advertised here would you let them keep their provider tag? But it only happened over on OGF ....
It doesn't matter if hazi broke specific rules at OGF. It was an illegal olympic-sized dick move against a competitor, for petty and stupid reasons.
This is kill -9, this person is a potential threat to any community due to a combination of low intelligence and malevolence.
Ban won't make any sense, as no one forbits him to create a new account. But IMHO he shouldn't sell anything again anywhere.
Not the same thing. As I said in the first part of my statement above, I suspended the provider tag when this came to my attention. Provider tags are removed, or never issued, to providers that the staff feels have a reasonable potential to be a danger to the community. Permanent removals or denials are generally decided by a majority vote of the staff, not just by any one person.
EDIT: It should be noted that there are other reasons, in addition to what I stated above, that a provider tag would not be issued or would be revoked but they don't apply to this situation.
So the provider tag portion wasn't as important as the fact that they never did anything wrong here. It was an attempt to show that some mistakes are big enough that they follow you. I don't really have an opinion so last I'll say on it.
@skorous I'm confused by this comment, FrankZ has just explained above that the provider tag was suspended so he can no longer sell anything in this board, so what did I missed?
Kudos for extremely fast disclosure, Romanian king is only one.
@FlorinMarian If you are confident in your new 20Gbps "Arbor" protection, think again, you made yourself many new enemies. I liked to laugh at your incompetence, but such retarded malicious move is a no go.
(this is not a threat, i'm just sure someone will do it)
@FlorinMarian care to clarify
I bench YABS 24/7/365 unless it's a leap year.
I think it's unfair to ban this boy based on what he does/did on OGF, but yes there should be certain requirements to being a provider here and anywhere else.
I bench YABS 24/7/365 unless it's a leap year.
@treesmokah @cybertech
This is what I can say about this situation:
if bad, why do?
and, if do, why public?
youtube.com/watch?v=k1BneeJTDcU
You "randomly" went to a competitors WHMCS. You "randomly" checked to see if files were available through non-standard methods. Then instead of informing Calin directly, like a reasonable person, you submitted your findings to LET with a snarky message and thread title that made it clear your actions were malicious. As I'm sure you expected, and to no surprise of anyone, the information and method YOU posted was used maliciously. Only after did you share your findings publicly did you then decide to inform him.
I'm not going to defend Calin, to be quite frank I think the two of your are cut from the same cloth and greatly lack business ethics. We'll all judge him in our own ways for his poor security practice that lead up to this event, but you really shot yourself in the foot. What did you expect to happen when you posted that thread? Everyone would clap for you, carry you on their shoulders and shower you with praise?
[ IncogNET LLC ] - Since 2020
[ The Internet Speech & Privacy Company ]
Why do you look at the situation in one way?
Calin, a provider in his turn, affects the image of the provider FlorinMarian in FlorinMarian's threads.
Why do you expect FlorinMarian to show true fraternity towards the one who tries to bury his image?
EDIT:
What was non-standard? I've used my browser to access his homepage and index.php was downloaded instead of interpreted and then did the same with configuration file to see if still works with that.
I'm not defending Calin. I think you two are more similar than unalike. I just think you took things too far, is all.
[ IncogNET LLC ] - Since 2020
[ The Internet Speech & Privacy Company ]
It is true that this action (posting) was based on hatred.
I had a pact with him to ignore each other after we had some tougher discussions in private, but after a while Calin returned to the old habit but loved by the community.
Being less popular than him, I couldn't post when I could see that he was lying about something, and that's how the hatred that raged yesterday accumulated.
What did Calin lie about?
Considering that I kept all these reasons in mind, it is clear that it affected me emotionally that my truths were ruining my image while his lies raised him far above me.
youtube.com/watch?v=k1BneeJTDcU
In the screenshots deleted from the LET, it was clear that Google Chrome had been used, just so that in my mind that vulnerability only existed for a fraction of a minute and not to be accused of who knows what hacking engineering.
understandable
youtube.com/watch?v=k1BneeJTDcU
LOL
Bro, you wrote bachelor thesis on DDoS attacks and hacking, you obviously know how to be a haxor.
Regarding whether you did it maliciously or not, I think its the first option. You whined about Calin in other threads already, you spotted opportunity to pick at him and you did.
I was judged for pettier things than this, it was 100% expected your tactic will backfire, I have no idea what were you thinking posting it. If any other member posted it, it could be justified for other reasons, but you are his direct competitor. It was clearly a dirty attack against your competitor. You could've stayed quiet, and wait for someone else to notice and then pick at him, instead you disclosed it yourself in the shittiest way possible.
If you given a fuck about ethics or his customers, you wouldn't disclose it like that.
I'm also aware you called certain people in the past to try and get Calin kicked out from Orange Romania(or try and ruin his business), knowing that, there is no doubt in my mind it was a malicious attack.
I rooted for you from your very beginnings with your "datacenter", It was extremely cool to me and I also wished I could have such setup for my homelab some day. But you fucked everything up, I'm just disappointed.
you are going on about what HE did as if this is some kind of justification for your action.
it simply is not.
if you find a vulnerability like that by accident simply act like a grown up and inform him. I probably could even understand if you'd just look the other way and ignore what you found.
however posting about it publicly like you did is a nogo , no matter what. the screenshot doesn't play a role at all.
what you posted is a direct prompt to go and look after it for anyone with possible malicious intent. you knowingly instigated people to harm your competitor.
like @MannDude said you have no business ethics at all and in the end this is the reason why you are failing.
it will always come back around to you one way or another. you build your bad reputation all by yourself with this kind of actions, so rather stop talking about all the bad things your competitors did to you.
it won't help and is no justification for your own behaviour anyway.
Yes, I am his direct competitor, as he is in my threads in which he drags the reputation I'm trying to build into the mud.
I would totally agree with you if there wasn't the essential element of the story: I went to the site and that shit was there, on the main page. Calin has no idea when that vulnerability was there, marking the time when I made the post the time when the cure appeared, which is not true. Between with/without my post the big difference is that more people saw that that vulnerability exists, nothing more.
There are hundreds of his clients who could have accessed the site all that time without my thread or even potential clients using backlinks from LET/LES. The only difference is that the community does not know about this incident, but the effects were the same for him.
i js thought bro curl'ed the homepage
There are hundreds of his clients who could have accessed the site all that time without my thread or even potential clients using backlinks from LET/LES. The only difference is that the community does not know about this incident, but the effects were the same for him.
People access backdoors all of the time, do see them posting it publicly?
The difference between revealing a vulnerability to the public, while it is not fixed, and letting the public find out the vulnerability, is that revealing will have a larger impact than the public finding it itself. Considering me, a person who has been into the interwebs for quite some time now, its almost always that some vulnerability that isnt disclosed is abused way less than the one which has been.
youtube.com/watch?v=k1BneeJTDcU
The database does not accept external connections and those credentials are useless without SSH access to the VM hosting the site.
Have you checked if that's the case before posting it?
Yes, no matter how retarded you think I am, I would not have publicly shown something like that for both ethical and legal reasons.
Well, you are retarded. You just admitted to trying to illegally access database of your competitor.
You talk nonsense and you know it, but I leave you, you have no reason to be on my side anyway.
Not anymore.
Why isn't @FlorinMarian banned here?
Why not admit it?
You were driven by revenge because of all the harassment from Calin and didn't think it through, and your move potential could harm all his customers.
Or did you check if the database port was open, so you were sure customers wouldn't be harmed? If so, I can't see you have done worse than Calin.
@FlorinMarian
What you did was absolutely not okay and it doesn't matter who it was or what you had against him. You don't publish something like that without giving the person concerned the chance to fix it and admit that there was a weakness.
If it hadn't been published by Calin, you could have published it, but not like this.
I'm really shocked that a hoster would do something like this, even though he should be aware that he himself could be in a similar situation at any time.
yk its actually pretty easy to spoof local connections, wont say how, and you probably know that.
youtube.com/watch?v=k1BneeJTDcU
He doesn't deserve to be banned here, he didn't do anything wrong here.
I'm also banned on LET but free to talk here as long as I play by local rules.
There was no harassment that I was aware of, shitting at someone on a public forum and in public threads in not harassment in any shape or form.
If he got intimidated by a kid with broken english and his caveman operation, I don't know what to tell you, Florin shouldn't have access to the internet.