Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Registered User
    Join Date
    Oct 2009
    Posts
    2

    Default cPanel and PCI Compliancy

    Hi,

    I'm looking into some solutions to vulnerabilities found by a PCI scanning box and was looking for some possible solutions that could be implemented. The problems are as follows:

    Account Name Enumeration: Requests of the following format hostname/~accountname will yeild a 403 error if the account name is valid and a 404 error if it is not.

    Mail Server Accepts Plaintext Credentials: Is there a simple way of implementing SSL over POP3?

    Thank you
    - Duncan

  2. #2
    cPanel Quality Assurance Analyst cPanelDon's Avatar
    Join Date
    Nov 2008
    Location
    Houston, Texas, U.S.A.
    Posts
    2,555
    cPanel/Enkompass Access Level

    DataCenter Provider

    Lightbulb

    Regarding the "/~username/" (mod_userdir) access, this access method can be disabled to alleviate the problem by enabling "mod_userdir" protection and ensuring that no sites/users are excluded so that none can be easily guessed via dictionary attack:
    WHM: Main >> Security Center >> Apache mod_userdir Tweak

    Documentation for Security Center and mod_userdir protection:
    WHM Security Center
    Apache mod_userdir Tweak

    Regarding POP3 and IMAP over SSL, it is possible to adjust and tweak the POP3/IMAP mail server configuration via WHM, including toggling the protocol, plaintext authentication, and SSL cipher list:
    WHM: Main >> Service Configuration >> Mailserver Configuration

    Here is our documentation further detailing this functionality:
    Mailserver Configuration
    Last edited by cPanelDon; 01-11-2010 at 10:33 PM. Reason: Revised documentation links

  3. #3
    Registered User
    Join Date
    Oct 2009
    Posts
    2

    Default One more question.

    Hi again,

    Thanks for the reply. I just had one more question pertaining to a PCI scan.

    Ports 2095, 2086, 2082 and 80 are all reporting the following vulnerability:

    Web Server Uses Plain-Text Form Based Authentication

    I realize that the developers will have to host the login on 443 as opposed to 80. However, I was wondering if 2095, 2086, and 2082 are utilized for authentication. Or, if they are simply used to return the Cpanel login script as I had read elsewhere.

    Also, if they are used for authentication, is there a workaround to avoid this vulnerability?

    Regards,
    Duncan

  4. #4
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,894
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb

    I think what you're looking for can be found in WHM > Tweak Settings Page > Redirection settings.

    Always redirect users to the ssl/tls ports when visiting /cpanel, /webmail, etc.

    Also check out the Security section on Tweak Settings page for other misc tweaks to lock down your security.

  5. #5
    cPanel Quality Assurance Analyst cPanelDon's Avatar
    Join Date
    Nov 2008
    Location
    Houston, Texas, U.S.A.
    Posts
    2,555
    cPanel/Enkompass Access Level

    DataCenter Provider

    Lightbulb

    To avoid having login data sent over a non-SSL connection or port, there is a new security feature in version 11.25 to require SSL for remote logins to force using SSL for access to cPanel, WHM, and Webmail.

    WHM: Main >> Server Configuration >> Tweak Settings
    * Require SSL for all remote logins to cPanel, WHM and Webmail. This setting is recommended.

    This is outlined in the 11.25 release notes (PDF) available at the following URL(s):
    cPanel 11.25
    ReleaseNotes < AllDocumentation < TWiki

Similar Threads & Tags
Similar threads

  1. PCI scan compliance - CentOS + cPanel
    By cyberiadmin in forum Security
    Replies: 3
    Last Post: 12-11-2009, 11:56 PM
  2. cPanel and PCI Compliancy
    By dmcrae in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-21-2009, 03:19 PM
  3. PCI DSS + Firewall NAT + cPanel
    By HappyPappy in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 07-29-2009, 01:06 PM
  4. PCI Compliancy - openssl & openssh
    By Belaird in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 12-21-2008, 07:27 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube