easyhosting Posted February 21, 2017 Share Posted February 21, 2017 Hi In Setup > General Settings > Others I have ' Allow Client Registration' unticked as it states ' Tick this box to allow registration without ordering any products/services' so leaving unticked should mean that no one can register unless they order goods or a service. well this fails as today i have had 3 sign ups without them ordering anything and each i have had to close accounts due to fraudrecord flags 0 Quote Link to comment Share on other sites More sharing options...
brian! Posted February 21, 2017 Share Posted February 21, 2017 any clues in the server logs as to how they did it? 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted February 21, 2017 Author Share Posted February 21, 2017 any clues in the server logs as to how they did it? Nothing, just indicates they signed up through register.php 0 Quote Link to comment Share on other sites More sharing options...
brian! Posted February 21, 2017 Share Posted February 21, 2017 Nothing, just indicates they signed up through register.php i'm not sure what to suggest with this... I suppose it's possible that there's a new exploit going around, and you could report the incident to WHMCS - but without knowing how they created the accounts, i'm not sure what WHMCS can do. another option, if you intend to keep registration disabled without ordering, might be to create a new register.php file or just remove it entirely... if registration is disabled, then the file is of limited use anyway - so if there is code within the encrypted register.php file that could be exploited into creating accounts, then creating a new basic file should remove that issue. although, it's also possible that creating a new file, and certainly removing it entirely, would result in the automatic updater putting it back - so that's something to bear in mind if you do this. 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted February 21, 2017 Author Share Posted February 21, 2017 Thanks Brian yes my next port of call will be a ticket to WHMCS, just thought i would ask on here first - - - Updated - - - i'm not sure what to suggest with this... I suppose it's possible that there's a new exploit going around, and you could report the incident to WHMCS - but without knowing how they created the accounts, i'm not sure what WHMCS can do. another option, if you intend to keep registration disabled without ordering, might be to create a new register.php file or just remove it entirely... if registration is disabled, then the file is of limited use anyway - so if there is code within the encrypted register.php file that could be exploited into creating accounts, then creating a new basic file should remove that issue. although, it's also possible that creating a new file, and certainly removing it entirely, would result in the automatic updater putting it back - so that's something to bear in mind if you do this. Just looked at the system module logs and it just shows Date: 21/02/2017 06:44 Module: rclbt Action: create customer with whmcs pwd 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.