Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member handsonhosting's Avatar
    Join Date
    Feb 2002
    Location
    Omaha, NE
    Posts
    150
    cPanel/Enkompass Access Level

    Root Administrator

    Exclamation PCI Compliance fail - Port 2096

    We received a report from ControlScan regarding port 2096 and the cookies being set on this port;

    Cookie Without HTTPOnly Attribute Can Be Accessed By Scripts - TCP: 2096

    A cookie without the HTTPOnly attribute could be susceptible to theft by cross-site scripting attacks.
    Cookies are a method of transmitting state information between web servers and clients. The HTTPOnly attribute specifies
    that a cookie may be used for HTTP requests only, and cannot be accessed by client-side scripts.
    There is a vulnerability in the way that some devices, especially web servers, store cookies on a user's system. If the
    HTTPOnly attribute is not set in the Set-Cookie header, the user-agent allows the cookie to be accessed by client-side script.
    If cross-site scripting vulnerabilities exist on the web server, then the cookie could be stolen by an attacker, possibly leading
    to session hijacking.
    Related CVE entries: CVE 2009-3566 McAfee IntruShield Network Security Manager
    For more information on the HTTPOnly attribute, see http://www.owasp.org/index.php/HTTPOnly OWASP.
    For more information about the session hijacking vulnerability in McAfee IntruShield Network Security Manager, see McAfee
    Security Bulletin SB10005.

    Solution:
    Modify web applications to set the HTTPOnly attribute for all cookies, or apply a patch or upgrade from your vendor.
    Information from Target:
    Service: 2096:TCP
    Received: Set-Cookie: logintheme=cpanel; path=/; secure; port=2096

    Any thoughts for a solution?

  2. #2
    Member disappointed's Avatar
    Join Date
    May 2007
    Location
    Houston
    Posts
    12

    Default

    set ports 2095:2096 to drop all attempted connections and you will pass PCI be sure to loop them back to localhost for cpanel and WHM or they will complain about it and shut down services...

    if you need access to these ports your self make sure you place your ip between the loopback and the drop statement to retain use of the service
    Last edited by disappointed; 08-19-2010 at 07:01 AM.

  3. #3
    Member
    Join Date
    Jun 2010
    Posts
    3

    Default

    Hey there,

    Two things should be noted here.

    1. This is a fairly minor potential attack vector and shouldn't necessarily dictate a full failure of PCI compliance.

    2 We've already patched this in our internal builds and will be rolling this out fairly soon in the 11.25.0 builds and above. Due to the nature of development, I can't necessarily give you an exact timeline, but the patch is ready to roll and should be released shortly.

  4. #4
    Member handsonhosting's Avatar
    Join Date
    Feb 2002
    Location
    Omaha, NE
    Posts
    150
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    No other scanning companies are reporting it as of yet, just ControlScan.

    Disabling the ports as suggested by "disappointed" is not an option as those ports are used for the webmail login.

    Thanks for the update regarding the fix being rolled into a new release.

Similar Threads & Tags
Similar threads

  1. PCI Compliance
    By richardsonchris in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 03-21-2011, 08:04 AM
  2. PCI Compliance
    By vajjas1 in forum Data Protection
    Replies: 9
    Last Post: 12-31-2010, 04:33 PM
  3. PCI Compliance Issue SSLv2 port 2078
    By kejebe in forum Security
    Replies: 1
    Last Post: 08-02-2010, 08:15 AM
  4. PCI Compliance
    By FourMat in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 02-19-2009, 10:09 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube