Jump to content

Recommended Posts

We’ve got something to share…

We recently received a lot of requests for support with a client password reset in the WHMCS admin area. As always, you said it and we acted on it.

We are excited to introduce our new module for admins to reset passwords on the WHMCS platform - Reset user password  module. With our Reset user password  module, admins can now securely reset passwords for clients without compromising their privacy. 

We understand the pain of recovering and resetting passwords for clients and have ensured that you can go through the process smoothly. 

 

Buy the module https://whmcsglobalservices.com/reset-client-password-whmcs-module/ here today. 

 

In case of any queries, you can find us here https://whmcsglobalservices.com/contact-us/

 

Always here to serve all your WHMCS needs.

Share this post


Link to post
Share on other sites

I'm confused as to how this is different from what's built in to WHMCS. They didn't remove this function, they just moved it to Users, which makes sense as Clients no longer have passwords - users do.

It's done in the WHMCS admin under The Client Account > Users > Click the arrow to the right of the user > Password Reset

That triggers the password reset process securely.

Edited by websavers

Share this post


Link to post
Share on other sites

This will work only if the emails are working correctly. admin cannot reset a password.

Share this post


Link to post
Share on other sites
20 hours ago, websavers said:

It's done in the WHMCS admin under The Client Account > Users > Click the arrow to the right of the user > Password Reset

The module allows you to specify a password. Not just send a password reset request.

Share this post


Link to post
Share on other sites
4 hours ago, DennisHermannsen said:

The module allows you to specify a password. Not just send a password reset request.

I see. I just assumed that couldn't have been the case given that it explicitly states above:

On 1/10/2023 at 4:56 AM, WGS said:

admins can now securely reset passwords for clients without compromising their privacy. 

However if the admin can see the password it most definitely compromises their privacy and is not, by definition, as secure as the built-in function.

Share this post


Link to post
Share on other sites
8 hours ago, websavers said:

However if the admin can see the password it most definitely compromises their privacy and is not, by definition, as secure as the built-in function.

What privacy? The admin already knows everything.

Share this post


Link to post
Share on other sites
19 minutes ago, Kian said:

What privacy? The admin already knows everything.

Huh? That's patently false. User passwords are one-way hashed and with the built-in password reset, strictly the user knows it. With this module that security/privacy is broken.

Example of this being a problem: staff member resets the password for clients. Staff member then leaves the company, and can no longer login as a WHMCS admin user, but has kept a record of all passwords changed. The now former staff member then uses those passwords to access client accounts or sells to the highest bidder. That's no good and definitely not private or secure.

Edited by websavers

Share this post


Link to post
Share on other sites
4 hours ago, websavers said:

Huh? That's patently false. User passwords are one-way hashed and with the built-in password reset, strictly the user knows it. With this module that security/privacy is broken.

I think Kian is referring to the fact that the admin already knows the clients' name, email, address, phone number and potentially other personal information.

The only way I would ever think of using a module like this is to set a temporary password for the user (if they no longer has access to their email account for example) and then force the user to set a new password after logging in.

Share this post


Link to post
Share on other sites
8 hours ago, websavers said:

Huh? That's patently false. User passwords are one-way hashed and with the built-in password reset, strictly the user knows it. With this module that security/privacy is broken.

I agree but on a side note, I am going slightly off topic to point out that the passwords for cPanel (and other modules) are wide open on the admin side. I think WHMCS should devote more time to cleaning things up like this.

There are plenty of different Software where you can reset a users password and temporarily see it (many ecommerce platforms for example). I'm not saying it's the right way but they exist.

Share this post


Link to post
Share on other sites
11 hours ago, websavers said:

Huh? That's patently false. User passwords are one-way hashed and with the built-in password reset, strictly the user knows it. With this module that security/privacy is broken.

Example of this being a problem: staff member resets the password for clients. Staff member then leaves the company, and can no longer login as a WHMCS admin user, but has kept a record of all passwords changed. The now former staff member then uses those passwords to access client accounts or sells to the highest bidder. That's no good and definitely not private or secure.

I am saying that passwords are irrelevant when it comes to staff members and more in general the company that runs eveything. This can also be extended to emails and even entire servers since you don't own the hard drive.

Who cares about passwords when staff members have access to things like servers, cPanel, Plesk, terminal, webmails, phpMyAdmin, third-party modules etc. In this context there's no way you can keep customer details private and secure. Let me make you a very scary example. Tomorrow I realease a free WHMCS module that solves all the problems we have ever had with this platform. 50k providers install it on their systems because it is just too good.

What stops me from running a script that grabs all servers passwords so I can edit millions of websites?
What stops me from getting hundreds of thousands of auth codes so I can transfer domains where I want?
What stops me from ransomwaring everything?

Surely not passwords. 99% of the times passwords are not meant to protect data from staff members, providers and maintainers. Their purpose is protecting end-users from other users. The only thing you can do as a company is trusting and choosing the right partners.

As for members leaving the company, for what is worth you could turn off password viewing/edit permissions.

Edited by Kian

Share this post


Link to post
Share on other sites

I think this answer from everyone above explains why security is so minimal these days. It really *does* make a difference, particularly if you have clients with domains - their Client Area password provides access to *their entire account (hosting, domains, etc)* whereas cPanel and Plesk passwords are limited to just the hosting panels.

With scenario 1 your clients just lost all their domains and hosting. Scenario 2 means they only lose their hosting. That's a pretty big difference.

Furthermore with SSO for hosting panels (which is now default in WHMCS), you *can* block staff (with some mods) from viewing those passwords as well.

On 2/6/2023 at 9:00 AM, Kian said:

What stops me from running a script that grabs all servers passwords so I can edit millions of websites?

If you're the only staff member, then sure. But many hosting companies have multiple staff that have limited access to client passwords and other such data in WHMCS.

On 2/6/2023 at 9:00 AM, Kian said:

What stops me from getting hundreds of thousands of auth codes so I can transfer domains where I want?

When a staff member is no longer employed, they could have easily saved passwords because of this module. They cannot do so with the built in WHMCS password changing system. And if they no longer have access to WHMCS when they're gone, they can't access those domains to get auth codes.

You need to think about *all* the possible angles, not just one, and then play the whatabout game to distract with other drawbacks.

Note that this is *exactly* how numerous recent data leaks occurred - because of former employees having access to systems they shouldn't have.

Edited by websavers

Share this post


Link to post
Share on other sites
On 2/6/2023 at 8:30 PM, Kian said:

when staff members have access to things like servers, cPanel, Plesk, terminal, webmails, phpMyAdmin, third-party modules etc.

@websavers Staff members doing such things what you say is rare and  @Kian is absolutely correct...staff members have access to the above things so I don't understand your privacy concerns ?

Also as @evolve hosting mentioned WHMCS needs to fix many other concerns where we are bound to use plain text...what about that ? Am I correct @evolve hosting ?

Share this post


Link to post
Share on other sites
49 minutes ago, ManagedCloud-Hosting said:

Also as @evolve hosting mentioned WHMCS needs to fix many other concerns where we are bound to use plain text...what about that ? Am I correct @evolve hosting ?

@ManagedCloud-Hosting I think they should conceal the passwords but it's been like this for years so I don't hold my breath thinking they'll make any changes for this.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


  • Similar Content

    • By ranojit
      Hi,
      I'm using SMTP.  My WHMCS sent me notification mail. I open the original mail and discover that the message ID always contaion @localhost instead of my domain name. It showing something like that,
      Message ID <fkfasdfwerkasjdfiasdfkjadfiasdfaef@localhost> But it should be like,
      Message ID <fkfasdfwerkasjdfiasdfkjadfiasdfaef@domain.com>  
      When I sent email manually from WHMCS it showing the domain name on the message ID. New client also get my WHMCS mail on spam folder for the first time. But if they mark my mail report not spam it's goes to inbox. I have a fewer clients and my WHMCS sent few email. I have valid SPF, DKIM, DMARC records. My server IP isn't blacklisted.
       
      I search everywhere but I didn't find the solution for this. Is there any one can help me?
    • By ModulesGarden
      1. Discover what our modules are up to!

      You can already view all previously uploaded advances and improvements at any time in our marketplace. What if you could also see what the next stages of development hide? This has just been made possible with the all-new section placed right next to the changelog.

      The implementation of Roadmap will show you that caring for customer engagement is one of the most important aspects taken into consideration at ModulesGarden. Want to know more and give the new feature a go?

      Continue reading on the ModulesGarden Blog!




      2. Zendesk For WHMCS 2.4.0

      You already know that we have a module in our offer that lets you include support tools powered by Zendesk into WHMCS and handle support tickets while bringing your clients unforgettable experience of customer care. Guess what - it’s just been updated with some fresh solutions!

      The description of the 2.4.0 update of Zendesk For WHMCS should start off with WHMCS users support - an addition which will send email notifications about the in-flow of new ticket replies to any user that participates in a conversation. Excited? Let us make you even more eager to give it a look. The latest version makes WHMCS user details fully synchronized with the Zendesk panel!

      See for yourself how easily you can up your customer service at an amazing 15% discount - give the changelog a thorough read!

      Read more about Zendesk For WHMCS 2.4.0!




      3. Password Manager For WHMCS 3.0 - 25% OFF

      In the business landscape of today’s world, cyber security is a top priority. Safe and long passwords are a great start, however remembering complex keystroke combinations can be too much of a challenge sometimes.

      The answer to these concerns is here - Password Manager For WHMCS 3.0! The latest huge update introduces an overhauled user interface with a brand new look, as well as support for Lagom Client Theme and WHMCS "Twenty-One".

      This fabulous module for extended safety has already been flooded with positive reviews, so delve deeper into the subject and find out how we have elevated it to new heights!

      Read more about Password Manager For WHMCS 3.0!




      4. PanelAlpha sets new trends in WordPress automation!

      Let us remind you of one more grand advancement - the next level in the development of our top-notch system for WordPress instances provisioning, PanelAlpha!

      The addition of Personal Hosting Toolkit will provide your clients with swift and painless control over their accounts by empowering them to handle domains, FTP accounts, DNS zones and more, all from the level of PanelAlpha.

      We all know how crucial a unique brand is nowadays. That’s why you will be able to customize the client area to fit yours however you desire with the Style Manager! Switch colors, enable shadows - from now on, you will be able to let out the inner artist.

      In fact, you can experience it right away via live demo, accessible at all times!

      Put theory into practice and see PanelAlpha in powerful action!




      Need Custom Software Development For Your Business?
      Get Your Free Quote Now! Specially for you we will adapt an application and its design to your own needs, create a new module or even a completely new system built from scratch!
    • By error 404
      Domain Search is not working for some domain
       
      I am using WHMCS 8. When i am trying to search for .org domain it's showing unavailable. 
      i have tried to fix this. not working... 
      how can I resolve this issue? 
      here is a Screenshot of my problem.....
       
       

       
       
       
       
    • By Tusher
      Hello,
      I am using WHMCS from recent time and I am new user of WHMCS. I have setup most things correctly.
      Now I am having issue in Manage Users section. Suddenly I noticed to have 6000+ users on the Manage User section. This is really horable. I deleted the entire WHMCS and reinstalled it but same problem is happening. everytime I refresh I see 3-5 new users are added. They are all spam and fake. I think my account get notice by any spammers or hackers.
      I have no easy way to delete those user, also I don't know who are they, where they came from and how I can stop them. Please help me 'Why this happening, any idea or solution?
      Thank you in advance.


    • By ashkan.khalili
      hello everyone ... 
      Today i have just update WHMCS to 8.3.1 and after update, when i try to login to admin or even as a client, on clientarea.php shows an error like this : 
      Whoops\Exception\ErrorException: Module 'apcu' already loaded in Unknown:0 Stack trace: #0 /home/..../public_html/hub/vendor/whmcs/whmcs-foundation/lib/Utility/Error/Run.php(0): WHMCS\Utility\Error\Run->handleError(32, 'Module 'apcu' a...', 'Unknown', 0) #1 [internal function]: WHMCS\Utility\Error\Run->handleShutdown() #2 {main} when i reload the page for several times, it redirects to "mysite.com/login" and gets user/password and then when i enter the user/pass again shows the same error ...!!!!
      i have tried a lot to find something but nothing is out there ! ! ! 
       
      would you guys please help me solve this problem !? 
       
      Thanks in advance 
  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated