LeMarque Posted July 9, 2021 Share Posted July 9, 2021 After re-installing WHMCS is am receiving "WHMCS Domain Synchronisation Cron Report" email that shows "Active Domain Syncs" and lists (shows) my WHMCS installation path with my renamed admin dir. Like this: https://mydomainname.com/whmcs/renamed_admin_file. Doesn't seem right that to me. I haven't setup any domains yet but in the past I would receive that report showing mine and client domains. Not the complete path to my renamed admin file. Thinking I have something configured incorrectly but don't know where. 0 Quote Link to comment Share on other sites More sharing options...
bear Posted July 9, 2021 Share Posted July 9, 2021 That link (my site and admin path) is included at the bottom of the report for me. If I recall correctly there's more than one email WHMCS sends that reveals that "secret" folder, and complaints about it have been ignored, mostly. I always felt it was a bad thing to send via email, but I guess they feel the benefit (as yet to be revealed) outweighs the risk of it being seen by anyone. 0 Quote Link to comment Share on other sites More sharing options...
LeMarque Posted July 9, 2021 Author Share Posted July 9, 2021 Ah, yes. Having munged my initial install I feel like I'm herding cats trying to get things back in place. Thanks for pointing out what I should have noticed in the previous emails. - L. 0 Quote Link to comment Share on other sites More sharing options...
steven99 Posted July 9, 2021 Share Posted July 9, 2021 Might be missing something here, but those emails should only be going to staff and not clients / public. So staff should already know that URL and so what is the risk here? Sure if the staff email is hacked, then the URL would be known but uh if that was the case you have more issues than them knowing the URL . Though would be nice for it to be an email template so you can remove if you wanted. 0 Quote Link to comment Share on other sites More sharing options...
LeMarque Posted July 10, 2021 Author Share Posted July 10, 2021 1 hour ago, steven99 said: Might be missing something here, but those emails should only be going to staff and not clients / public. So staff should already know that URL and so what is the risk here? Sure if the staff email is hacked, then the URL would be known but uh if that was the case you have more issues than them knowing the URL . Though would be nice for it to be an email template so you can remove if you wanted. Thanks #steven99 for checking on what might be happening. Nope, the emails aren't going to clients. I just failed to understand why it was listing the Admin dir. 0 Quote Link to comment Share on other sites More sharing options...
bear Posted July 10, 2021 Share Posted July 10, 2021 1 hour ago, steven99 said: what is the risk here? The email is not encrypted end to end. It passes through any number of servers on it's way, in plain text/html. If anyone has access to any of those servers along the way (for whatever reason), they have the "secret" folder. That's one more step towards doing "bad things", and the main reason that folder is changed in the first place. It is pointless risk to include it, as it does nothing for the admin, and might (however slight the risk) expose paths. 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.