Special characters in contact details - domain registering = Fail

Started by lowprofile, July 03, 2014, 07:35:59 AM

lowprofile

Hi

I am having huge problems with customers who got a "special" character in their contact details.
My domain registrar can't accept these characters in the API, which makes a failure....

95% of my users are from europe, mainly germany, scandinavia. It is very common for them to have this character.

e.x. öäüúæøåáí etc...

The module itself is NOT developed by hostbill, and is working all right when not having these letters.

I then saw this feature:


Unfortunately it is not working, i thought it may remove or made them "neutral"
What is more worse is that hostbill now do some server encoding before sending the form when registering domain from client area.
This made my temporary fix to broke, i inserted a code in the module to convert these letters before feeding the API. This is also not working anymore.


I have really hit the wall now, and any input will be appreciated!


nibb

This feature stopped working a couple of months ago.

I noticed that domains with accented characters like the ones you mentioned started to fail like 4 months or so. My install had that option checked so its seems it just stopped working.

I reported that it as bug but the bug tracker is gone now.

This issue is actually very old, 1 or 2 years back, then he created that feature which fixed the problem and some how a couple of versions back the bug came back.

All domains with accented characters will mainly fail now with most registrar modules. This are the little bugs which show you that Hostbill is trash. Not even 50$ scripts have this issues with domains anymore. The problem is actually with the orders form.

Did you noticed that you can enter invalid characters in the domain form and hostbill allows you to order is just fine?

Example, try to order a domain like this:
example--.com

It works !!! He is just slopping and takes little care to details and attention. His modules are full of bugs, even with a few clicks you can break them or make them do something which are not supposed to happen because he does not even bother to make some basic quality checks or testing before release. One bugs fixed, 100 new ones introduced.

Hell, I even found bugs that allow you to hijack complete domains and servers from any company using hostbill and I reported that to Hostbill 1 year ago and the holes are still there. He just does not care.

You say the module is not developed by hostbill? I had this problem with modules only developed by hostbill and with 3 different registrars. So even his own modules suffer from this.

BRJP

Quote from: nibb on July 03, 2014, 11:37:00 PM
Hell, I even found bugs that allow you to hijack complete domains and servers from any company using hostbill and I reported that to Hostbill 1 year ago and the holes are still there. He just does not care.

This is a little worrying!  You say this is a bug but this sounds like a major security flaw to me.  Have I misread or are you saying there is a serious security vulnerability here?
Kind regards,
Bradley Porter
--------------------
Find out more about SaneChoice Services at: https://www.sanechoice.cloud/