Jump to content

Ticket address is public?


jkook

Recommended Posts

Hi.

I just found out if I copy and paste ticket address, everyone can see the contents of tickts.

Is it normal?

 

Because if it's public, it can be crawled by google, so I shouldn't write an account information or password.

One of my clients asked password, that's why I am wondering,

Link to comment
Share on other sites

the big issue is that even if search engines don't crawl the links, some other scripts do.

 

like traffic monitors/scripts.

 

i recently found some tickets indexed by a traffic monitor i use on my pages.

 

i had to prevent this, and I wrapped the source code of supportticketview.tpl between:

 

{if $loggedin} 

and

{else}
You must be logged in
{/if}

 

that seemed to do the trick, however, the ticket can be viewed by another user if logged in

Link to comment
Share on other sites

  • WHMCS CEO

If you do that, that then makes your ticket system unusable for non registered users. The ticket number/secret key combo should be enough to keep search engines from indexing it unless the user goes and posts their unique ticket link in public somewhere.

 

Matt

Link to comment
Share on other sites

i use a traffic monitor on my website.

 

the script goes into footer.tpl.

 

of course, the script indexes the ticket pages.

 

there is no way of removing it from some pages is it?

 

can i use footer2.tpl for some pages and footer.tpl on others?

 

is there any kind of discrimination possible in the footer.tpl? like:

 

{if $page = supportticketview}
do nothing
{else}
insert the monitor script
{/if}

Link to comment
Share on other sites

*bump* I just tested and found out the issue to be real.

 

A customer asked me if my ticketing system is being crawled by google ... I understand the issue now, I thought it was blocked when not logged in. At least those tickets are hard to access by a search engine...

 

But do you think hackers who knows how whmcs works be able to figure out how to generate those ticket id's?

Link to comment
Share on other sites

i doubt they can generate it.

 

but as I said, i have a traffic monitor and here is some public output for visited pages from last week:

 

http://stat.trafic.ro/stat/megahost/pagini-intrare/saptamana/#stat

 

note the last 3 entries on the bottom:

 

viewticket.php?tid=317657&c=PXjH8bqv

viewticket.php?tid=247167&c=8XbFCEF1

 

these records are public.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated