Jump to content
[MUST READ] Forum Rules ×

Client Area for my MOFH Reseller


Recommended Posts

EDIT: Fixed my issue with LOGGED, so I'll stick with that for now :) 

 

 

 

Hi,

I'm looking to use a client area for my MOFH Reseller.

Are there any good ones out there that are secure?

If there isn't, could someone recommend me a good Login/Signup page? I've tried LOGGED but I'm getting a "posting error" when redirected to the iFastNet page...
 

Thanks in advance. 

 

Edited by DCG Network
Link to comment
Share on other sites

35 minutes ago, DCG Network said:

I've seen MOFHY, but the creators page on GitHub states that "It isn't secure"

 

yep,Because MOFHY Can XSS Injection.And MySQL Injection

XSS Is not really important(i think xD. it just destroy Your Admin Panel.You Can Remove Account On PMA

but MySQL Injection ,it could delete your all Accounts.it can access,modify,delete your MySQL Database

MOFHY Can prevent MySQL Injection. but cant fully prevent MySQL Injection.

And Lot Of Security Problem..I GUess?

anyway you still can use it,u can use it If You can fix

if u cant fix,you still can use!Just becareful! :)

Edited by MeTooIDK
Link to comment
Share on other sites

40 minutes ago, DCG Network said:

Hi,

I'm looking to use a client area for my MOFH Reseller.

Are there any good ones out there that are secure?

If there isn't, could someone recommend me a good Login/Signup page? I've tried LOGGED but I'm getting a "posting error" when redirected to the iFastNet page...
 

Thanks in advance. 

 

Logged,You Can Ask PlanetTheCloud to resolve it

there is PDN Discord Server https://discord.com/invite/mmEWpnwB8D

---

 

Edited by MeTooIDK
Link to comment
Share on other sites

Hello, 

Unfortunately there isn't any other client area for MOFH available at this moment. You can either use mofhy and patch the security issues yourself or create your own custom client area using the API (docs: https://api.myownfreehost.net/)

Project Logged is the best currently out there for a login-signup page (at least I'm not aware of something else). You can enable the debug mode and share here the errors and how it's happening so maybe we can help resolve the issue you got.

Link to comment
Share on other sites

20 minutes ago, Dimitris said:

Hello, 

Unfortunately there isn't any other client area for MOFH available at this moment. You can either use mofhy and patch the security issues yourself or create your own custom client area using the API (docs: https://api.myownfreehost.net/)

Project Logged is the best currently out there for a login-signup page (at least I'm not aware of something else). You can enable the debug mode and share here the errors and how it's happening so maybe we can help resolve the issue you got.

No problem, will enable the Debug mode and share results here.

 

Link to comment
Share on other sites

Hi, 

First of all, I've given up on BoxBilling!

This is the error I'm getting with LOGGED, after being redirected to the iFastNet signup page (ifastnet.com/register2.php)

Posting Error, #923578257 (https://auth.hostbydcg.cf/ , auth.hostbydcg.cf), Please contact support

 

 

Link to comment
Share on other sites

On 4/4/2022 at 3:32 AM, MeTooIDK said:

You Can Remove Account On PMA

Can you say more about this?

 

On 4/4/2022 at 3:32 AM, MeTooIDK said:

but MySQL Injection ,it could delete your all Accounts.it can access,modify,delete your MySQL Database

MOFHY Can prevent MySQL Injection. but cant fully prevent MySQL Injection.

And Lot Of Security Problem..I GUess?

Can someone say more about this?

Link to comment
Share on other sites

  • 3 months later...

No, MOFHY is still insecure. I just checked it again after you posted that,  and every version of MOFHY on GitHub has the same vulnerability in the Admin area. 
 

Some versions have tried to cover it up, but failed. It is still explotable is the same way it was before. 

Link to comment
Share on other sites

6 hours ago, TinkerMan said:

No, MOFHY is still insecure. I just checked it again after you posted that,  and every version of MOFHY on GitHub has the same vulnerability in the Admin area. 
 

Some versions have tried to cover it up, but failed. It is still explotable is the same way it was before. 

Thank for responding.

Link to comment
Share on other sites

6 hours ago, TinkerMan said:

same vulnerability in the Admin area. 

You can use directory privacy to prevent access to the admin area.

---

Also, there is a new client area called "Xera", which seems promising. The security vulnerabilities seem to have been patched, although we are still searching for them.

There is an active forum for it at fourm.xera.eu.org

Edited by User51
Link to comment
Share on other sites

11 hours ago, User51 said:

You can use directory privacy to prevent access to the admin area.

Correct, but it is very easy to brute force that. As long as you chose and obscure username and password it will be fine. But client accounts will be just as vulnerable, and you cannot directory privacy that without the username and password being public. 
 

I do like where xera is going, although I have not kept as close of an eye on it since it is a bit more complicated. Hopefully it will be deemed good for release in a year or two!

Link to comment
Share on other sites

There's only one MOFHY?

It most likely is just a customized MOFHY. May I ask, where did you download this from?

3 hours ago, TinkerMan said:

I do like where xera is going, although I have not kept as close of an eye on it since it is a bit more complicated. Hopefully it will be deemed good for release in a year or two!

It's not that bad once you figure out how the files are organized. I'd reccommend trying Xera @Lordson, it's in better shape than MOPHY is

Edited by User51
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...