Thanks ADAM
we deal with more then 25 servers .. and when some body hack our WHMCS account he hacked 25 server plus DirectI and Enom accounts
what I did in my first post is copy and past from phpmyadmin .. the passwords you can see them .. and they are non encrypted ,, this how the hacker can get an access to DirectI and Enom accounts
CHOMD 777 disabled
we don;t run CGI
phpEXE run on our servers
Suchion
we do run virus and trojan scan in daily basis
Register global disabled on our servers
we have port limit to IP address in SSH lo gin
with all of those .. if some body has an access to WHMCs admin account .. nothing of all above features will help you .. and 25 servers will hacked in 5 min's
some thing that I can thing about .. log in to server management from admin area should has other password !! at least some more protections .. where we can feel safe
This is an open discussion .. for every body how to improve the security in WHMCS
regards,