Possible hacking?
Probably, your account has been hacked? Hope it is not....Just contact them via an online support chat.
Bump: Dear Members;
We hope that you are enjoying investment experience with Track Invest Inc and will continue in the future. Lately, we have discovered some hacking attempts in which some member’s account details were changed but don’t panic as your funds are safe and secure.
Also we observed hacking attempts to administrator panel and our own payment processors which were failed by our quick actions and mitigation. Below are only few highlights, if interested we can give details information to concerned persons.
As you know, we earlier shifted our DDOS protection from BlackLotus (www.blacklotus.net) to BlockDos and didn’t face any attacks again. Now, we are moving our hosting as well from BlackLotus. We will advise all members and ADMIN of the HYIPs that BlackLotus is a SCAM hosting. Never use their hosting or DDOS Protection, this is one of the reasons that HYIPs hosted by BlackLotus disappear very quickly. It is not because of Admin, it is because of Black Lotus. We are the sharing this info with you which no admin share earlier.
We are elaborating the details below. Our findings of problems are as follows; (Our web administrator and GoldCoders admin assisted us in these findings).
Black Lotus has root and Cpanel access even on Dedicated Servers. They will edit the following flies in Cpanel folders for HYIPs which use GoldCoders script.
· They will replace your original “admin.php” file (even it is encrypted) with new one. We advise you to always check the size of the file. The original file size is more than 500kb; the replaced one will have less than 100 kb.
· Then they will edit the file “deposit.libertyreserve.confirm.tpl” and add their Liberty Reserve account. When member will deposit, it will not go to original admin account and you will shout on admin that where is my deposit? But admin never received this deposit. Also, modified file will have script that payment more than 1K, 3K or 5K and more will go to Black Lotus account and less will go to admin account. Here again, always check the file size.
· They edit the file “%254^%%2545287560^deposit.libertyreserve.confirm. tpl” as well for same reason as above.
· When BlackLotus failed to make the above changes, they came up with new idea for stealing funds; When admin process withdrawals using API (LR, PM or Egopay, obviously when API is turned on; they will add their fake accounts and all payments will go to their accounts until all funds vanished. For admins, please never save your API details in the admin panel. When using mass payment; always set daily limits in Liberty reserve and Egopay API. Also, every time you make payments using API, use new passwords.
· Check your CPanel, WHM access logs and you will find last IP accessed being from BlackLotus and when you ask why they accessed server? There will be no explanation.
These are the few problems we have faced and despite all odds and losses, we continue paying our investors and will continue for minimum 2 years.
We are now moving servers to BlockDOS and website will be down for 24 hours. We appreciate your patience during the down time. We are trying our best to provide you seamless investment services.
We request again, don’t panic and visit our face book page when website is down due to shifting of our servers.
Thank you,
Lawrence Newman"
Last edited by rlghyipexplorer; 02-27-2013 at 10:21 AM.
Reason: Rewrite
|