We are one of the users affected by the recent wave of attacks involving websites using Balbooa extensions.
During the recovery of our website, we performed an extensive analysis of both the filesystem and the database. We found several pieces of information that we believe may be useful to your developers in investigating the ongoing security situation.
Some of our findings concern malware artifacts and recovery observations, but we also found an issue in Balbooa source code that we believe should be reviewed by your developers.
We do not know whether this issue was related to the compromise of our website, and we do not want to make any unsupported claims.
For security reasons, however, we would prefer not to publish the technical details on the public forum before your team has had an opportunity to review them.
We have seen that other users reporting security-related findings have been able to provide additional technical information privately.
Could someone from the Balbooa team please provide us with an appropriate private contact method for submitting our findings?
We are happy to provide all relevant technical details privately.
Thank you.
Replies are visible only to logged in members with an active subscription.