Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Using THT in Production (Albeit Reskinned)
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Using THT in Production (Albeit Reskinned)

We are currently using WHMCS but because of the recent problems I am looking for another solution.

Would there be anything wrong with Reskinning and Adding features to THT?

Comments

  • This is an awful idea

  • seriesnseriesn Member
    edited October 2013

    Sure. Why not. Don't forget to share :)

  • @Spencer said:
    This is an awful idea

    Care to elaborate on why?

    @seriesn said:
    Sure. Why not. Don't forget to share :)

    Course :)

  • Are there any exploits?

  • MaouniqueMaounique Host Rep, Veteran

    If it will become popular, you can be sure there will be attacks against it. The guy after solus and whmcs will probably not publish exploits against them, but I do not know any popular serious piece of code without vulnerabilities in the past.

  • DomainBopDomainBop Member
    edited October 2013

    @mcmyhost said:
    Are there any exploits?

    current version 1.2.6 -no exploits published yet
    v 1.2.5 - CSRF attack vector on the mass email page
    v1.2.4 a few major security problems which were fixed in 1.25
    v 1.2.3- "TheHostingTool (THT) 1.2.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/pear/Mail/smtp.php and certain other files. "
    http://www.cvedetails.com/cve/CVE-2011-3809/
    v1.22 Multiple CSRF Vulnerabilities
    http://www.exploit-db.com/exploits/14337/

    Every version has had security problems and some of those vulnerabilities were critical. If you look at the dates when the vulnerabilities were first discovered and when they were patched you'll see that some of them weren't patched until months after being discovered...and you're thinking of switching to this from WHMCS?

  • there is THT Reworked 1.3.10 which is a "fork" of THT with bugfixes and more functions.

    The author is also working on "Reworked Manager":

    Reworked Manager will in the end, be able to do everything that WHMCS and BoxBilling can do and more. Plus it will be compatible with WHMCS modules and BoxBilling Modules through it's own abstraction layer. This means that if you've ever purchased a WHMCS or BoxBilling module, you will be able to continue to use it on Reworked Manager.

Sign In or Register to comment.