Browse Category: Annoucements

New payment gateways for HostBIll

New payment gateways integrations: Coinify and CoinGate

Digital currencies, especially bitcoin despite all controversies around it, are becoming more and more popular. There’s a growing number of online businesses accepting various virtual currencies. Digital currencies are valued for the convenience, ease of use and innovation. And as at HostBill innovation is one our our key goals, we’re happy to introduce two new payment gateways integrated with HostBill that will allow you to accept bitcoin and other digital currencies payments: Coinfy and CoinGate. Continue Reading

Security Advisory – HostBill version 2013-12-14

We’ve just released security update for HostBill, as a response to potentially dangerous XSS Vulnerability.

Applying update
To apply security update please download and update HostBill to the lateste 2013-12-14 version.
You can also use our auto-upgrade plugin to perform this automatically.

Upgrading to new version: https://hostbill.atlassian.net/wiki/spaces/DOCS/pages/491585/Upgrading+to+new+version
Using auto upgrade plugin: https://hostbill.atlassian.net/wiki/spaces/DOCS/pages/491588/Auto-Upgrade+plugin

We believe that this vulnerability is not known to the public. Its severity depends on admin area protection.
KBKP Software always encourages our clients to take extra steps for protection:
https://hostbill.atlassian.net/wiki/spaces/DOCS/pages/1212438/Security

Big thanks to team Rack911 (https://www.rack911.com/) for identifying and reporting this problem.

Security Advisory – HostBill versions 4.x

In the last couple hours we’ve released patch for HostBill versions 4.x available from auto-update plugin and to download directly from:

https://hostbillapp.com/clientarea/patches/hostbill_patch4.6.4_4347.zip

For manual patch apply please extract archive contents in main HostBill directory.
We strongly recommend upgrading to the latest HostBill version (4.6.4 – archive also contains patched files)

Patched vulnerability
We’ve been notified about brute-force attack possible to be performed by logged in customers into other client’s accounts.

Patch was introduced immediately for auto-upgrade feature.