Jump to content

Warning: you might be sharing your admin URL


snake

Recommended Posts

Just discovered a security issue today.

If you use a custom admin URL, beware, that replying to tickets via email (rather than logging into the admin) may be sharing your admin URL.

I noticed this today, when a suspicious looking customer tried to login to my admin.

I then noticed that my reply to his ticket, which I had replied to from my mobile phone, had the admin URL in it, as WHMCS had not stripped out the previous email I was replying to, which was the notification email from whmcs about the ticket, which has a link your you admin in the content.

So you might want to avoid replying to your tickets via email.

 

Link to comment
Share on other sites

if you have a custom admin url, then it is supposed to be a secret, that's the point. Otherwise you tend to get lots of hack attempts.

WHMCS normally strips previous replies from emails when it imports them, but this seems to have stopped working.
I also do not reply to tickets via email very often, only when not in front of my computer, so have not noticed this before.

Link to comment
Share on other sites

Nothing directly, just another thing that makes no sense with WHMCS. Reveal the "secret" admin URL in various places, have paid "branding free" that only applies to the front end (but not many emails or the entirety of the admin, where they feel we need to be reminded what software we're paying for) and so on. 

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated