Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


WHMCS WebHost License Bypass Loophole - Page 3
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

WHMCS WebHost License Bypass Loophole

13

Comments

  • Links been removed but guessing its where you add the whmcs.com and localhost.whmcs.com to the /etc/hosts file or something I seen ages ago for research purposes.

  • hotsnow said: I think WHMCS don't care about this, I've seen some similar posts which talking about this bug at least 1 year ago, but the bug still existing until now, lol

    Maybe I need to re-post the link to gain WHMCS's attention lol

  • drserverdrserver Member, Host Rep

    AnthonySmith said: "Excuse me madam, does this tissue smell like chloroform to you?"

    Hahaha You just made my day

  • retryretry Member
    edited January 2014

    Should have posted in hakz fawrum

    runs

  • Seriously though,

    This same method works on just about all software; no null required. Five seconds with a .js webserver, or a python webapp + hosts entries can get you WHMCS, cPanel/WHM, RVSkin, Softaculous, SolusVM .....

    Yet, you can save yourself (as a consumer) against these here:

    http://www.whmcs.com/members/verifydomain.php

    http://verify.cpanel.net/

    These are important links.

  • @HardCloud said:
    Seriously though,

    This same method works on just about all software; no null required. Five seconds with a .js webserver, or a python webapp + hosts entries can get you WHMCS, cPanel/WHM, RVSkin, Softaculous, SolusVM .....

    Yet, you can save yourself (as a consumer) against these here:

    http://www.whmcs.com/members/verifydomain.php

    http://verify.cpanel.net/

    These are important links.

    This bug can bypass whmcs license verification and shows 'this domain is authorized to use WHMCS' on the page you provided

  • @GreenVine said:
    This bug can bypass whmcs license verification and shows 'this domain is authorized to use WHMCS' on the page you provided

    Good for you. Philip doesn't care.

    Or whoops, this isn't SolusVM.

    Still, they won't fix it for years.

  • GreenVineGreenVine Member
    edited January 2014

    So I will re-post the link and article as WHMCS not respond: http://go.green-vine.net/yc2ik.

    Not null its software therefore is legal.

  • @GreenVine said:

    Not really, no. The reverse engineering required, etc etc; it's a thin line of legality, and you're just trying to get a rise out of people posting it on LET.

  • @HardCloud said:
    Not really, no. The reverse engineering required, etc etc; it's a thin line of legality, and you're just trying to get a rise out of people posting it on LET.

    WHMCS's source code is downloadable in China.

  • @GreenVine said:
    WHMCS's source code is downloadable in China.

    WHMCS source code is downloadable from WHMCS, what's your point?

    It's only ioncube, five seconds on Google will show you an online decode, etc etc.

  • @GreenVine said:
    WHMCS's source code is downloadable in China.

    But LET/LEB is on US soil.

  • Also i could use one valid license then install it to unlimited server. And its not nulled. You could use the other domains and whmcs well , without license issue. Bad thing: only one domain will be valid if they check it at whmcs website. But you could use the license withut nulled.. without any issue :). Trick the license eaaasyyy :). Using the latest 5.2.16 version , installed by softcalous. Without license error. Easy steps. >Reissue license > Install whmcs with softcalous > reissue license > insall :P , now you have 2 legal WHMCS what is not nulled and up to date. Just one of them will be "valid by whmcs". Goof trick? Course. Will whmcs solve this problem? Never...

  • 哎呀,你都是调皮 :P

    Wow, you are naughty.

  • @ZweiTiger :: The number of times you can reissue your license is limited. Also, the installations will periodically perform a remote check with the WHMCS licensing server. When that happens, whichever one isn't authorized will be invalidated. While the client area will continue to function, you won't be able to access the admin area until it's re-validated.

    Thanked by 1Mark_R
  • @TekStorm_James said:
    ZweiTiger :: The number of times you can reissue your license is limited. Also, the installations will periodically perform a remote check with the WHMCS licensing server. When that happens, whichever one isn't authorized will be invalidated. While the client area will continue to function, you won't be able to access the admin area until it's re-validated.

    I can.. acces it. :). Maybe its a mistake or not.. who know. I am able to acces the admin.

  • You will be able to use both, initially, until one decides to performs its remote check.

  • TekStorm_James said: You will be able to use both, initially, until one decides to performs its remote check.

    I ever saw somebody put licensing28.whmcs.com into /etc/hosts and fake a Active license response. Working fine in older version but not test it in 5.2.16.

    Thanked by 1Mark_R
  • @GreenVine said:
    I ever saw somebody put licensing28.whmcs.com into /etc/hosts and fake a Active license response. Working fine in older version but not test it in 5.2.16.

    When it comes from your server and goes to theirs, can't you inspect the packets, see what response it gets, and just fake that from then on?

  • @mpkossen said:
    When it comes from your server and goes to theirs, can't you inspect the packets, see what response it gets, and just fake that from then on?

    Certainly that's possible.

  • luissousaluissousa Member
    edited January 2014

    @mpkossen said:
    When it comes from your server and goes to theirs, can't you inspect the packets, see what response it gets, and just fake that from then on?

    Why would anyone do it instead of nulling it? It is not hard at all.

  • fileMEDIAfileMEDIA Member
    edited January 2014

    mpkossen said: When it comes from your server and goes to theirs, can't you inspect the packets, see what response it gets, and just fake that from then on?

    As long as they not using SSL and encryption which encrypted the session timer token in an encrypted memory range. But where should it use without any license? When you cannot pay the money (15$..) for a license your business model is crap und you should close it..

  • @fileMEDIA said:
    As long as they not using SSL and encryption which encrypted the session timer token in an encrypted memory range. But where should it use without any license? When you cannot pay the money (15$..) for a license your business model is crap und you should close it..

    Sure. It was purely theoretical what I was suggesting.

  • @xcubehost said:
    WHMCS is cheap enough as it is, if you cant afford a few dollars a month on a billing system, then you realy should not be in the business to begin with!

    Better yet, get an owned license if you don't like paying monthly, it's only $249.95, and only $45/yr to get the support and updates.

  • fhneric said: Better yet, get an owned license if you don't like paying monthly, it's only $249.95, and only $45/yr to get the support and updates.

    lol Eric you survived?

  • EvoEvo Member

    http://blog.whmcs.com/?t=80970

    You could get up to $5000 for reporting such a bug.

  • skagerrakskagerrak Member
    edited January 2014

    @Evo said:
    http://blog.whmcs.com/?t=80970

    You could get up to $5000 for reporting such a bug.

  • If you can't afford 15$ , get out of business now.... (much cheaper with hosting from many companies, free from SingleHOP with a reseller service...)

  • netomxnetomx Moderator, Veteran

    @HardCloud said:
    If you can't afford 15$ , get out of business now.... (much cheaper with hosting from many companies, free from SingleHOP with a reseller service...)

    Funny reading that from you

    Thanked by 1srvrpro
  • @HardCloud said:
    If you can't afford 15$ , get out of business now.... (much cheaper with hosting from many companies, free from SingleHOP with a reseller service...)

    I must say again that this is for RESEARCH purpose.

Sign In or Register to comment.