@Jatin Sahani Apparently the support section of mBuilder gives away too much info. The hacker is obviously an mBuilder user if not even the developer. A large portion of the mBuilder code is obfuscated, a technique similar to malware. I get a notification every time someone creates a support ticket. I can view the profile of the user. In the profile I can see website where mBuilder is installed as well as license key. All attacker needs is a customer account to access mbuilder and upload the payload. He already has a list of all mailwizz installations running mBuilder from the support section.
We have already fixed it and we got aware of such a hole by our customers only i thought this hole was in our latest version which is not yet publicly released, Our developer will test it first thing in the morning and we will provide a patch right after that, request you guys to disable Mbuilder for now to prevent him from hacking it again.
Thanks, Apologies for the inconvenience.
@Jatin Sahani - should know about this since it was a security issue in mbuilder where the files were not checked at uploads.
I also provided guidance in how to fix the given security error, which is very serious.
He should have fixed it by now and notify all customers, since again, that's a serious thing.
@Jatin Sahani - should know about this since it was a security issue in mbuilder where the files were not checked at uploads.
I also provided guidance in how to fix the given security error, which is very serious.
He should have fixed it by now and notify all customers, since again, that's a serious thing.
Yes, but this was with our latest version which is not publicly released, none the less we will release the patch tomorrow for sure, as its 12+am at the moment and my developer will test it once more and release the patch for all our customers.You sure?
Yes, but this was with our latest version which is not publicly released, none the less we will release the patch tomorrow for sure, as its 12+am at the moment and my developer will test it once more and release the patch for all our customers.
Thanks.
As i told you above, i personally contact twisted for the latest version which is NOT released. He reviewed the code and told me about this issue, which my developer fixed but we haven't even released this version till now. Well now we have to release it for all our customers.What date did he inform you?
As i told you above, i personally contact twisted for the latest version which is NOT released. He reviewed the code and told me about this issue, which my developer fixed but we haven't even released this version till now. Well now we have to release it for all our customers.
Also this hacker is well trained i assume as we don't know yet how he got all the details of our customers and there mw installations.
We are not strong at hacking protection please lets not create a scene here now, even big companies get hacked all the time, i understand the issue at hand as its very late here i personally can't do anything until tomorrow once i reach office, as i will push my developer to test this hole once more and review the code once more and then we will push the patch tomorrow only.
I can provide steps via PM to any one who got hacked and needs to get back into his backend panel. Also again i will request all our customers to disable the extension for now and change the backend passwords and Database passwords as well.
Thanks
we haven't even released this version till now
@Jatin Sahani I still receive email notification for support tickets created by other users. Please fix your support platform. It gives away too much information.
Hi,
we get this error on saving email on editor
jquery.min.js:4 POST http://mydomain.com:9000/compile net::ERR_CONNECTION_REFUSED
and it doesnt save
Have someone a fix?
Regards
Hi @Allante Johnson and @Jatin Sahani ,
You are still developing and selling mBuilder? Or maybe they're on vacation in the Caribbean?
I bought a license two days ago. I have received NOTHING. I have sent you several emails, written from the contact form of your website, from your web chat,... And I don't receive a reply!
Do you guys have a problem? I don't understand a customer service that bad.
yes, I do it https://support.mbuilder.co/client/view_ticket/74Hi, please open a ticket and we can take a look at the issue.