Jump to content

Sending the authinfo by email to admin-c


Remitur

Recommended Posts

Hello.

 

A user of WHCMS can see directly the authinfo of every domain of him.

 

This is wrong and a security fault (even if more or less every registrar in the world make the authinvo available on screen).

It's a fault because with some TLD (.ie. .it) the authinfo is all you need to trasfer and trade the domain: no other check by email is required.

So, anyone can access to your WHMCS control panel, can access to the authinfo of every domain of yours.

And if he keep note of them, he can transfer and trade them even years later...

 

The solution is not showing the authinfo in the control panel, but to send it by email to admin-c or registrant contact of the domain.

 

And my question is: does exist any way, any trick, any plugin or module to do so? :?:

Link to comment
Share on other sites

Whether an authorisation/epp code is displayed or emailed is dependant on what registrar module(s) you use - each registrar implements it differently

 

Sure?

I work with three different registrars (Opensrs, Resellerclub, hexonet).

For any domain the authinfo request drive the customer to following URL:

domain.ext/clientarea.php?action=domaingetepp&domainid=5

which (I think) is a common page of the "Six" template... isn't it?

There's any other Registrar which has different behaviour in this page?

Any way, any idea to how override it?

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated