hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Software and Control Panels : Hosting Software and Control Panels Tutorials : WHMCS Security: How To Remove The "Forgot your password?" Link From Admin Login Area.
Reply

Hosting Software and Control Panels Tutorials Tutorials specifically for control panels and other hosting software.
Forum Jump

WHMCS Security: How To Remove The "Forgot your password?" Link From Admin Login Area.

Reply Post New Thread In Hosting Software and Control Panels Tutorials Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 05-30-2012, 09:32 AM
cd/home cd/home is offline
MANAGEMENT KING!
 
Join Date: Nov 2009
Posts: 8,193
Post

WHMCS Security: How To Remove The "Forgot your password?" Link From Admin Login Area.


Hello,

To stop the "Forgot your password?" link from displaying on your admin login area on WHMCS.

Simply edit and add the following line (below) to your root WHMCS "configuration.php" file:

Quote:
$disableadminforgottenpw = true;
By disabling this feature it will reduce the risk of someone gaining access to your WHMCS admin area should your email account be compromised.

Regards,

Reply With Quote


Sponsored Links
  #2  
Old 05-30-2012, 09:35 AM
rsfk rsfk is offline
Newbie
 
Join Date: Dec 2011
Posts: 14
Thank you. Doing this right now.

Reply With Quote
  #3  
Old 05-30-2012, 09:54 AM
cd/home cd/home is offline
MANAGEMENT KING!
 
Join Date: Nov 2009
Posts: 8,193
Quote:
Originally Posted by rsfk View Post
Thank you. Doing this right now.
Thank You, Please help spread the word

Regards,

Reply With Quote
Sponsored Links
  #4  
Old 05-30-2012, 10:06 AM
kbeezie kbeezie is offline
Web Hosting Master
 
Join Date: Jun 2010
Location: Grand Rapids, Mi
Posts: 1,193
ditto.

Do they happen to have a list of variables you can set in the config at WHMC's documentation?

Reply With Quote
  #5  
Old 05-30-2012, 10:15 AM
SirMarcel SirMarcel is offline
Web Hosting Master
 
Join Date: Jun 2010
Posts: 584
Setup > General Settings > Security > Disable Admin Password Reset [x]

Reply With Quote
  #6  
Old 05-30-2012, 10:27 AM
cd/home cd/home is offline
MANAGEMENT KING!
 
Join Date: Nov 2009
Posts: 8,193
Quote:
Originally Posted by kbeezie View Post
ditto.

Do they happen to have a list of variables you can set in the config at WHMC's documentation?
I dont think they do

Quote:
Originally Posted by SirMarcel View Post
Setup > General Settings > Security > Disable Admin Password Reset [x]
Although this is available for newer WHMCS installations...

The older ones dont have this option available as it was only implemented into WHMCS during the Version 5.0 release

Reply With Quote
  #7  
Old 05-30-2012, 10:32 AM
SirMarcel SirMarcel is offline
Web Hosting Master
 
Join Date: Jun 2010
Posts: 584
is there any particular reason one wouldn't want to upgrade to the most recent version? surely just by having an outdated installation you're risking your system being compromised

Reply With Quote
  #8  
Old 05-30-2012, 10:34 AM
cd/home cd/home is offline
MANAGEMENT KING!
 
Join Date: Nov 2009
Posts: 8,193
Quote:
Originally Posted by SirMarcel View Post
is there any particular reason one wouldn't want to upgrade to the most recent version? surely just by having an outdated installation you're risking your system being compromised
Mainly because people have heavily modified WHMCS installations which includes various modules so some people find it easyer to stay patched and focused on security rather than being an upgrade junkie

A patched WHMCS 4.5 is just as secure as an patched WHMCS 5.0

However this isnt a debate about release notes and release candidate security, Its merely a tutorial to help all WHMCS users disable the link.


Last edited by cd/home; 05-30-2012 at 10:38 AM.
Reply With Quote
  #9  
Old 05-30-2012, 10:38 AM
kbeezie kbeezie is offline
Web Hosting Master
 
Join Date: Jun 2010
Location: Grand Rapids, Mi
Posts: 1,193
Quote:
Originally Posted by cd/home View Post
Mainly because people have heavily modified WHMCS installations which includes various modules so some people find it easyer to stay patched and focused on security rather than being an upgrade junkie

A patched WHMCS 4.5 is just as secure as an patched WHMCS 5.0
Adding to this, in theory you only lacking 'new features' and such, as any security patches they release tend to be available for as far back as version 4.0 (as you would have noticed from their most recent patch). The upgrades aren't really for security fixes but rather features and such.

Reply With Quote
  #10  
Old 05-30-2012, 10:53 AM
cd/home cd/home is offline
MANAGEMENT KING!
 
Join Date: Nov 2009
Posts: 8,193
Quote:
Originally Posted by kbeezie View Post
Adding to this, in theory you only lacking 'new features' and such, as any security patches they release tend to be available for as far back as version 4.0 (as you would have noticed from their most recent patch). The upgrades aren't really for security fixes but rather features and such.
Thank You for adding additional information on the subject.

The more information we can get around about securing WHMCS the better

However I shall forward my opinion about having this included to the WHMCS documentation to Matt.

Regards,


Last edited by cd/home; 05-30-2012 at 11:01 AM.
Reply With Quote
  #11  
Old 06-07-2012, 10:09 AM
SafeSrv SafeSrv is offline
Junior Guru
 
Join Date: Apr 2008
Location: UK
Posts: 232
Why not just VPN the backend altogether ? i mean this is going to do very little security wise !

Reply With Quote
  #12  
Old 06-07-2012, 10:10 AM
Simplex-Ed Simplex-Ed is offline
Aspiring Evangelist
 
Join Date: Sep 2011
Posts: 370
Quote:
Originally Posted by SafeSrv View Post
Why not just VPN the backend altogether ? i mean this is going to do very little security wise !
Indeed, a lot of people miss this...

Reply With Quote
  #13  
Old 06-07-2012, 03:45 PM
kbeezie kbeezie is offline
Web Hosting Master
 
Join Date: Jun 2010
Location: Grand Rapids, Mi
Posts: 1,193
Quote:
Originally Posted by SafeSrv View Post
Why not just VPN the backend altogether ? i mean this is going to do very little security wise !
Wouldn't that throw off the licensing? (i.e.: thinks the app being hosted on a internal/VPN IP then won't let you login on account of the licensing) ?

Reply With Quote
  #14  
Old 06-07-2012, 08:19 PM
SafeSrv SafeSrv is offline
Junior Guru
 
Join Date: Apr 2008
Location: UK
Posts: 232
Quote:
Originally Posted by kbeezie View Post
Wouldn't that throw off the licensing? (i.e.: thinks the app being hosted on a internal/VPN IP then won't let you login on account of the licensing) ?
No it won't affect licensing at all, i have always restricted backends to either my ISP IP or VPN, its the best way to keep your backend secure.

Reply With Quote
  #15  
Old 08-20-2012, 08:02 AM
KiBaHost KiBaHost is offline
Newbie
 
Join Date: Jul 2012
Posts: 10
Thanks for tutorial.

Reply With Quote
Reply

Similar Threads
Thread Thread Starter Forum Replies Last Post
"Forgot your password?" link does not work in VZCC error 'Password restore.... ideas VPS Hosting 2 07-28-2010 03:07 AM
Typo3 Security Question for "Forgot Password" bsimoneau Web Design and Content 0 04-30-2008 01:31 PM
What link do you use for your "client" management area? mrzippy Running a Web Hosting Business 1 10-08-2006 09:26 PM
MCHost - please fix your "secure" client area login form... mrzippy Reseller Hosting 6 08-05-2003 11:29 PM
I want to make a "forgot my password" form...but I can't....help? hdezela Programming Discussion 10 07-23-2003 12:55 PM

Related posts from TheWhir.com
Title Type Date Posted
WHMCS Releases Version 5.2 of Web Hosting Billing Solution Web Hosting News 2013-04-14 22:35:37
Web Host Billing System WHMCS Deals with Support Challenges, Network Issues Web Hosting News 2012-09-14 10:36:58
Hackers Use Social Engineering to Compromise CloudFlare CEO Gmail Account Web Hosting News 2012-06-04 10:40:16
ZNet Launches WHMCSExtras Site for Web Hosting Billing Platform Addons Web Hosting News 2012-02-10 11:48:25
SSL Certificate Distributor The SSL Store Adds WHMCS Integration Web Hosting News 2011-06-30 16:49:59


Tags
whmcs, whmcs admin disable forgot password, whmcs forgot password disable, whmcs security

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?