Results 1 to 4 of 4

Thread: Host Access Control - Proxy Subdomains Bypass

  1. #1
    Member mbd5882's Avatar
    Join Date
    Apr 2005
    Location
    Manchester, United Kingdom
    Posts
    60
    cPanel/WHM Access Level

    Root Administrator

    Default Host Access Control - Proxy Subdomains Bypass

    Hello,

    I'm trying to block WHM access to our company network only. I created a Host Access Control rules as below.

    whostmgrd OFFICEIP allow # Allow office staff access
    whostmgrd LOCAL allow # Allow local API requests
    whostmgrd ALL DENY # Deny all others access

    This worked fine and all other IP addresses attempting to access WHM through ports 2086 and 2087 were given a forbidden message.

    However, WHM can still be accessed through the cPanel proxy subdomains as whm.customerdomain.tld as this is through Apache.

    How can I block WHM access through the proxy subdomains also? Is my only solution to disable the proxy subdomains?

    I appreciate any help on this issue.

    Regards,
    Asad Haider

  2. #2
    cPanel Staff cPanelTristan's Avatar
    Join Date
    Oct 2010
    Location
    somewhere over the rainbow
    Posts
    7,611
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Host Access Control - Proxy Subdomains Bypass

    Hello Asad,

    That's a really good question that I've never realized that it was the case. I would have thought the wrapper itself for whostmgrd process couldn't be bypassed by proxy subdomains, but I've just tested this on my machine where I did a deny just for my IP for whostmgrd and whm.mydomain.com bypassed the restriction.

    The only way I could see around this issue would be to only allow WHM on a dedicated IP that you aren't using for anything else, then to only allow that proxy subdomain for whm on that dedicated IP. At that point, you could restrict all port traffic to that IP to only the allowed IPs.

    Alternatively, you could remove the whm proxy subdomain entirely and only have the others.

    Thanks!
    cPResources: Support Options | More Support Options | Forums Search | cPanel.net Site Search | Mailing Lists(Alt) | Docs
    -- Tristan, Technical Analyst III, Forums Specialist, cPanel Tech Support

    Submit a ticket | Check an existing ticket

  3. #3
    Member mbd5882's Avatar
    Join Date
    Apr 2005
    Location
    Manchester, United Kingdom
    Posts
    60
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Host Access Control - Proxy Subdomains Bypass

    Hi Tristan,

    Sorry about the two threads, all our staff have access to this account so I should have posted it under here.

    Thanks for looking into it, I thought you would be aware of the issue already. I came across it accidentally while testing if the blocking was working and couldn't find a fix or similar reported issue on the forums.

    I guess I'll disable proxy subdomains for now to prevent access. We'll take a look into running it on a dedicated IP address and blocking it that way.

    Would you guys be looking into this further? or letting people know about it?

    Thanks,
    Asad

  4. #4
    cPanel Staff cPanelTristan's Avatar
    Join Date
    Oct 2010
    Location
    somewhere over the rainbow
    Posts
    7,611
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Host Access Control - Proxy Subdomains Bypass

    Hello Asad,

    I'm going to go through our internal reports to see if anything is mentioned about it and then inquire about the issue. It isn't necessarily a bug, but it might well be something needing documented on our site if it hasn't been.

    Since I was not aware of it, I'd imagine many others aren't aware of it either. There's no warning in either the proxy subdomains tweak setting nor in Host Access Control about these bypassing the restrictions.

    Thanks!
    cPResources: Support Options | More Support Options | Forums Search | cPanel.net Site Search | Mailing Lists(Alt) | Docs
    -- Tristan, Technical Analyst III, Forums Specialist, cPanel Tech Support

    Submit a ticket | Check an existing ticket

Similar Threads

  1. Host Access Control
    By LampedWeb in forum Security
    Replies: 1
    Last Post: 04-13-2011, 11:08 PM
  2. Replies: 8
    Last Post: 06-24-2009, 06:20 PM
  3. Host Access Control (block IP access)
    By meeti in forum New User Questions
    Replies: 5
    Last Post: 05-13-2008, 12:39 AM
  4. host access control
    By salvatore333 in forum cPanel & WHM Discussions
    Replies: 1
    Last Post: 01-31-2008, 06:08 AM