Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Registered User
    Join Date
    Jan 2012
    Posts
    1
    cPanel/Enkompass Access Level

    Website Owner

    Default notification when email forwards added as safeguard

    I'm a WordPress developer who has several thousand clients on many different web-hosts, most of which run cPanel.

    We've recently uncovered a security exploit likely caused by cPanel password theft, but in each case the hacker added a email forward for each of the users email addresses, forwarding all emails to his own account, presumably so that he could sift through them for other passwords, personal data, etc.

    It got me thinking that a very logical extra layer of protection should be added to cPanel. What I propose is this: when an email forward is set up, and email should be sent to the address being forwarded saying basically "an email forward has been set up to address X. If you did this, take no action, if not, log in and delete the forward and change your cPanel password."

    The silent nature of email-forwarding hacks makes this a very appropriate failsafe to add. Gmail just instituted very similar policies to safeguard against unwanted email forwards after some high-profile hacking issues, see:

    Why do I have a forwarding notice? - Gmail Help
    Gmail Forwarding Filter Alerts About Filters Forwarding Email to Other Accounts

    Would the developers consider adding this security improvement?

  2. #2
    cPanel Staff cPanelJared's Avatar
    Join Date
    Feb 2010
    Location
    Houston, TX
    Posts
    1,066

    Default Friendly Moderator Note

    I moved your post to our Feature Requests section, which our developers do review and use to consider future improvements and additions to cPanel.
    For hands-on assistance, please reference our new support information page: Where should I go for support?
    cPResources: Support Options - Submit a ticket here - Additional Support Options - Forums Search - Mailing Lists(Alt) - Documentation


    -- Jared Ryan, Technical Analyst, cPanel Technical Support

  3. #3
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: notification when email forwards added as safeguard

    Quote Originally Posted by Jared Henderson View Post
    Would the developers consider adding this security improvement?
    Depends on how much feedback and what kind of feedback this thread receives.

    However, what you mention requires that essentially the server is either rooted already or the cPanel account has been exploited. To do what you mention, they can simply delete any email account, redirect anything anywhere, delete the entire website etc. at that point.

    IMHO, it would be better to use the security functionality in cPanel&WHM such as source IP checking when logging in (combined with the security questions), cookie authentication, source IP checking on the cookies, CSRF protection and the multitude of other existing security functionality to avoid being "pwn3d" in the first place.

  4. #4
    Member monarobase's Avatar
    Join Date
    Jan 2010
    Location
    France
    Posts
    387
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: notification when email forwards added as safeguard

    +1 for this feature. We have not encountered this problem as we manually reset passwords and don't allow users to reset passwords by e-mail, but it defenetly makes sense for those that do.

Similar Threads & Tags
Similar threads

  1. email forwards not working
    By SetLar8 in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-07-2007, 06:33 AM
  2. Email Forwards going into WebMail Also
    By sexshun in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 11-13-2005, 09:42 AM
  3. Creating EMAIL Forwards
    By ZaireWeb in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-20-2004, 03:20 AM
  4. Email Forwards Delayed
    By MarkB in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-24-2003, 02:32 PM
  5. Email forwards..
    By haze in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 02-27-2002, 01:29 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube