Jump to content

Request from ResellerClub resellers for better security


EhsanCh

Do you vote for this ?  

11 members have voted

  1. 1. Do you vote for this ?



Recommended Posts

Hi friends.

As you may know , resellerclub uses your full username and password for API authentication so if you were to be compromised (for example by a bug or insecure hosting) he can access to all of your domains.

the solution is a separate and limited API user , and it can be done only by resellerclub.

i request all of you to vote for this request on Resellerclub feedback system at folowing link :

 

http://feedback.resellerclub.com/forums/19909-general/suggestions/2492951-please-pay-more-attention-to-security

Please pay more attention to security

 

To Vote , simply login to your resellerclub account , at TOP Right of control panel you see a feedback link , click on it to login to feedback system and click on above link. or search by subject : "Please pay more attention to security"

Edited by EhsanCh
Link to comment
Share on other sites

But if someone can access API password , he can login to resellerclub and add his ip to allowed list. he can also move all domains to another panel. someone that has api password , has unlimited access.

 

You should create Company account and remove API Access function or any functions without needed for automatic provisioning and management.

 

And if you lost password of resellerclub api account through whmcs so you may lost much than it :( . Should take care security of your system.

 

But I think Resellerclub's reseller can set permission for sub-reseller, I afraid about move service function.

Link to comment
Share on other sites

You should create Company account and remove API Access function or any functions without needed for automatic provisioning and management.

 

And if you lost password of resellerclub api account through whmcs so you may lost much than it . Should take care security of your system.

 

But I think Resellerclub's reseller can set permission for sub-reseller, I afraid about move service function.

-Company account cannot access API function and cannot be used in whmcs.

-yes, we shuld take care security of our system . but nothing is 100% secure, specyally in shared hosting. every time a bug may be found in our hosting softwares or in whmcs... so ?

- no permission can set for subreseller , and even if it can set it is not usefull because we need it under main account.

Link to comment
Share on other sites

  • 4 months later...

Dear resellerclub resellers, as you see these days , any hosting can be accessed by hackers, even WHMCS servers.

so please vote for this feature to avoid losing your domains :

 

You have to login to your resellerclub panel , then click on feedback link on top right of your control panel, then click this link :

 

http://feedback.resellerclub.com/forums/19909-general/suggestions/2492951-please-pay-more-attention-to-security

Link to comment
Share on other sites

  • 4 weeks later...
With the API, wouldn't it be possible to get all the information too? They should log all the actions, but it seems their system is very secure at this moment. They even limit the IP access to the API, so only your server IP will be able to connect to the API.

 

Be sure it is secure if:

- CURL SSL is used

- Accessing the API from a browser with http is NOT SECURE and should be avoided.

 

And yes, any action made through the API is logged.

 

Regards,

Marco

Link to comment
Share on other sites

  • 3 weeks later...

Only your server IP can connet to API, BUT if someone have api password (that is same as your web panel password) he can login to resellerclub control panel and access to your whole account from any ip. even change your username and password or transfering domains.

Edited by EhsanCh
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated