We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 25551 ☆ A M B ☆
    • 1,231 Posts
    I am currently integrating WHMCS with modx and it’s working so far. I created an AJAX/Mootools login system that validates the users login details via cURL. WHMCS uses md5+salt for passwords and I have managed to validate the users input against this hash.

    I am using SESSIONS to control access, block persistent failed login attempts and to control a custom advert database.

    My question is how do I test to make sure my system is secure? I am validating the AJAX login system by sending requests and responses in JSON, I’m using firebug to see what is sent and what the response is and it is only showing the limited amount of data I would want passed. But I know there is no such thing as full proof. What steps should I take to test if my ajax system is secure?

    I trust that WHMCS is fairly secure using their own login forms but I want to use AJAX for the nice effects!

    I would be happy to put a link up to the work with a test account for anyone who knows what to check for?

    Thanks.
      Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
      AugmentBLU - MODX Partner

      BLUcart - MODX Revolution E-Commerce & Shopping Cart
      • 16702 ☆ A M B ☆
      • 536 Posts
      Hi rossco,


      i have no solution for your question, but i have another question about integration...
      Can you share how you realize an integration?

      Thanks in advance
        palma non sine pulvere
        • 4971
        • 964 Posts
        +1 on that one...
        that would be a great extra for MODx and WHMCS

        Are you saying that your customers login in MODx and then you share or extend
        that login to WHMCS?

        I use MODx as my website and then my customers go to the support or other WHMCS area
        and then log in the normal way...

          Website: www.mercologia.com
          MODX Revo Tutorials:  www.modxperience.com

          MODX Professional Partner
          • 25551 ☆ A M B ☆
          • 1,231 Posts
          Hi guys,

          I use WHMCS as the user system. I created a plugin that connects to the WHMCS API and validates the users name and password against the MD5+$salt password stored in the WHMCS database. This allowed me to write my own plugin to query the WHMCS database for the validated user. I’ve done all this using SESSIONs,Mootools/Ajax and PHP and is working pretty well. Also in the plugin, I set the internalKey with the WHMCS client ID and ad them to a user group, update modx’s database if required etc. There’s no need to ask them for a password in modx if they have already been validated by WHMCS so the plugin takes care of showing the user on the modx site aswell.

          I’ll setup a test account in WHMCS and let you see it working. I’m just making sure it’s as secure as I understand how to make it... I’m still a bit of a PHP noob.

          Does anyone know the best way to handle $_POST from a user? I want to protect against injection so I need to know the best way to strip out unwanted stuff.

          Would $myusername = mysql_real_escape_string($_POST[’username’]) be enough?
            Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
            AugmentBLU - MODX Partner

            BLUcart - MODX Revolution E-Commerce & Shopping Cart
            • 11055 ☆ A M B ☆
            • 3,112 Posts
            For the username context, I’d prefer to make a sanitizing function, which passes ALLOWED characters (not rejected) using preg_match.
            I believe, username will only contain alphanumerics [0-9a-zA-Z], underscores ’_’, and spaces ’ ’.
            Don’t bother about injection scripting.

            So the code would become
            $myusername = sanitize($_POST[’username’]);
              Rico
              Genius is one percent inspiration and ninety-nine percent perspiration. Thomas A. Edison
              MODx is great, but knowing how to use it well makes it perfect!

              www.virtudraft.com

              Security, security, security! | Indonesian MODx Forum | MODx Revo's cheatsheets | MODx Evo's cheatsheets

              Author of Easy 2 Gallery 1.4.x, PHPTidy, spieFeed, FileDownload R, Upload To Users CMP, Inherit Template TV, LexRating, ExerPlan, Lingua, virtuNewsletter, Grid Class Key, SmartTag, prevNext

              Maintainter/contributor of Babel

              Because it's hard to follow all topics on the forum, PING ME ON TWITTER @_goldsky if you need my help.
              • 25551 ☆ A M B ☆
              • 1,231 Posts
              Thanks, I just remembered that WHMCS uses the email to sign in only so will this still work?
                Ross Sivills - MD AugmentBLU Edinburgh, Scotland UK
                AugmentBLU - MODX Partner

                BLUcart - MODX Revolution E-Commerce & Shopping Cart
                • 11055 ☆ A M B ☆
                • 3,112 Posts
                then add dot ’.’ and at ’@’, isn’t it?

                Here is a simple example so you can figure out.
                Please remember, this works vise versa, so you must think reverse way for your case:

                <?php
                    /*
                     * to check the valid characters in names
                     * TRUE means BAD!
                    */
                    private function _has_bad_char($characters) {
                        $bad_chars = array (
                                "U+0000", "/", "\\", ":", "*", "?", "'", "\"", "<", ">", "|", ";"
                                , "@", "=", "#", "&", "!", "*", "'", "(", ")", ",", "{", "}", ","
                                , "^" , "~" , "[" , "]" , "`"
                        );
                        foreach ($bad_chars as $bad_char) {
                            if (strstr($characters, $bad_char)) return TRUE;
                        }
                    }
                


                The usage is:
                <?php
                if ($this->_has_bad_char($_POST['name'])) { // I use class in this case
                 echo $lng['badchars'];
                 return false;
                }
                


                EDIT: found my email validation script here
                <?php
                function check_email_address($email) {
                    if (!preg_match("/^([a-zA-Z0-9])+([\.a-zA-Z0-9_-])*@([a-zA-Z0-9_-])+(\.[a-zA-Z0-9_-]+)*\.([a-zA-Z]{2,6})$/", $email)) {
                        return false;
                    }
                    return true;
                }
                

                <?php
                    if(check_email_address($e) == FALSE) {
                        $_report .= '<h2>'.$lng['email_err'].'</h2>';
                    }
                
                  Rico
                  Genius is one percent inspiration and ninety-nine percent perspiration. Thomas A. Edison
                  MODx is great, but knowing how to use it well makes it perfect!

                  www.virtudraft.com

                  Security, security, security! | Indonesian MODx Forum | MODx Revo's cheatsheets | MODx Evo's cheatsheets

                  Author of Easy 2 Gallery 1.4.x, PHPTidy, spieFeed, FileDownload R, Upload To Users CMP, Inherit Template TV, LexRating, ExerPlan, Lingua, virtuNewsletter, Grid Class Key, SmartTag, prevNext

                  Maintainter/contributor of Babel

                  Because it's hard to follow all topics on the forum, PING ME ON TWITTER @_goldsky if you need my help.