kicon Posted April 12, 2015 Share Posted April 12, 2015 hi recently i have a major database been hacking. i found many client accounts been login from a single IP and hacking my client accounts information. is there any development right now can prevent login from a single IP of multiple client accounts? i would appreciate with your help. 0 Quote Link to comment Share on other sites More sharing options...
bigideaguy Posted April 12, 2015 Share Posted April 12, 2015 It could be created however I don't think it will solve your issue, it will simply delay the inevitable. You should try to find out where the hack originated, how did they get the passwords or perform the login? 0 Quote Link to comment Share on other sites More sharing options...
sentq Posted April 12, 2015 Share Posted April 12, 2015 hirecently i have a major database been hacking. i found many client accounts been login from a single IP and hacking my client accounts information. is there any development right now can prevent login from a single IP of multiple client accounts? i would appreciate with your help. we your ask for can be done easily, but it would better to find out where and how this hacking happened? 0 Quote Link to comment Share on other sites More sharing options...
brian! Posted April 13, 2015 Share Posted April 13, 2015 recently i have a major database been hacking. i found many client accounts been login from a single IP and hacking my client accounts information. is there any development right now can prevent login from a single IP of multiple client accounts? i would appreciate with your help. are you sure the database has been hacked? if I remember correctly, if you are using a WordPress front-end site for WHMCS, with the free WHCMS Bridge plugin, it will show your server IP instead of the client IP in the logs... if that is so, then it might appear that lots of clients are logging in from a single IP... but in reality they are not. the easiest way to tell would be to check whether this single IP is the same as your server. 0 Quote Link to comment Share on other sites More sharing options...
SavandBros Posted April 14, 2015 Share Posted April 14, 2015 Not sure how you can force that with no third-party module. But my thoughts on single IP is that, you're running behind proxy and IPs might get same as others. 0 Quote Link to comment Share on other sites More sharing options...
brian! Posted April 14, 2015 Share Posted April 14, 2015 You can ban IPs from within WHMCS - http://docs.whmcs.com/Security/Ban_Control - but those bans would apply to everyone using that IP. 0 Quote Link to comment Share on other sites More sharing options...
kicon Posted June 4, 2015 Author Share Posted June 4, 2015 hi i would suggest when whmcs gonna add this security feature like "preventing a single IP to be logined from multiple client accounts".... for example if there are 3 or more clients accounts been logined from the same IP and that IP will be auto add to banned list and for further review from admin. please let me know when you gonna add this feature. i think this a major security situation for whmcs. - - - Updated - - - hi i would suggest when whmcs gonna add this security feature like "preventing a single IP to be logined from multiple client accounts".... for example if there are 3 or more clients accounts been logined from the same IP and that IP will be auto add to banned list and for further review from admin. please let me know when you gonna add this feature. i think this a major security situation for whmcs. 0 Quote Link to comment Share on other sites More sharing options...
bigideaguy Posted June 4, 2015 Share Posted June 4, 2015 hii would suggest when whmcs gonna add this security feature like "preventing a single IP to be logined from multiple client accounts".... for example if there are 3 or more clients accounts been logined from the same IP and that IP will be auto add to banned list and for further review from admin. please let me know when you gonna add this feature. i think this a major security situation for whmcs. - - - Updated - - - hi i would suggest when whmcs gonna add this security feature like "preventing a single IP to be logined from multiple client accounts".... for example if there are 3 or more clients accounts been logined from the same IP and that IP will be auto add to banned list and for further review from admin. please let me know when you gonna add this feature. i think this a major security situation for whmcs. This is a flawed way of doing security. It is better to find out how someone is able to get your clients credentials and fix that issue. I have clients who own or are part of several companies who would trigger such a ban. It seems like it would cause more problems than it would solve. It is also very easy to switch to a different IP. So the ban would really only harm your regular users who trigger it by accident. 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.