Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Member
    Join Date
    Jul 2010
    Posts
    7

    Thumbs down cPanel User Feature Manager security risk

    Here is my problem. I have a hosting account with a provider using cPanel. I need to set up a secondary user for the email admin and have done this, assigning him the role of Email_maintainer with no FTP access.

    In order for him to be able to log in to the cPanel, he first has to use my master login credentials and then his own username and password.

    This is surely a security risk as he then has my master login details. Although he cannot use these to access any cPanel areas that are outside of his assigned roll, he could use my login to gain FTP access to my site files via a third party FTP client.

    The flaw in the system seem to be that he is required to use my master login before he can enter his own login. Unless I am missing something here, there appears to be no way around this dilemma.

    I have tried disabling FTP access for the main account and then creating a Webmaster roll for myself with FTP enabled. However the system does not allow any secondary users FTP access if the main user account has this disabled. Very frustrating.

    I am hoping that someone out there may be able to solve this but I fear it is something that would have to be addressed by the developers

  2. #2
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,892
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb

    There is no way that I know of to add a secondary user account to maintain email, or anything else inside a cPanel account.

  3. #3
    Member
    Join Date
    Jul 2010
    Posts
    7

    Default

    Quote Originally Posted by Infopro View Post
    There is no way that I know of to add a secondary user account to maintain email, or anything else inside a cPanel account.
    Well it's quite easy, you just go to Prefererences, User-Feature manager and turn the feature on.

    You can then add new users with limited or full access. They have their own login but they also have to use your master login to access the secondary user login.

  4. #4
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,892
    cPanel/Enkompass Access Level

    Root Administrator

    Question

    Quote Originally Posted by Robolovsky View Post
    Well it's quite easy, you just go to Prefererences, User-Feature manager and turn the feature on.

    You can then add new users with limited or full access. They have their own login but they also have to use your master login to access the secondary user login.
    Please be more specific about where this area is located, please. I'm low on coffee today. Where is this Preferences > User Feature Manager at exactly?

  5. #5
    Member
    Join Date
    Jul 2010
    Posts
    7

    Default

    Quote Originally Posted by Infopro View Post
    Please be more specific about where this area is located, please. I'm low on coffee today. Where is this Preferences > User Feature Manager at exactly?
    Well in my cPanel, "Preferences" is the first horizontal box at the top of the page. User-Feature manager is the last icon in that box. I know that web hosts can set these up any way they want so maybe you don't have that feature on yours.

  6. #6
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,892
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb

    Quote Originally Posted by Robolovsky View Post
    Well in my cPanel, "Preferences" is the first horizontal box at the top of the page. User-Feature manager is the last icon in that box. I know that web hosts can set these up any way they want so maybe you don't have that feature on yours.
    As mentioned, there is no way to add a secondary user that I'm aware of. This sounds like something your host has added as you mentioned, so thats where you'll need to seek assistance with this issue.

    Sorry I can't help more than that, no experience with that feature.

  7. #7
    Member
    Join Date
    Jul 2010
    Posts
    7

    Default

    Quote Originally Posted by Infopro View Post
    As mentioned, there is no way to add a secondary user that I'm aware of. This sounds like something your host has added as you mentioned, so thats where you'll need to seek assistance with this issue.

    Sorry I can't help more than that, no experience with that feature.
    I have done some digging and discovered that this feature appears to be part of a skin management system for cPanel called RVSkin (cPanel Theme - RVSkin, a great experience for you, reseller, and clients).

    I have taken up the query with them.

    Thanks for trying.

  8. #8
    Member reactorh's Avatar
    Join Date
    Aug 2005
    Posts
    56

    Thumbs down

    Quote Originally Posted by Robolovsky View Post
    Well it's quite easy, you just go to Prefererences, User-Feature manager and turn the feature on.

    You can then add new users with limited or full access. They have their own login but they also have to use your master login to access the secondary user login.
    So this feature is worthless cause i dont wanna to give my credentials to a limited user....
    Reactorhosting - Creando y ofreciendo la mejor solución!

Similar Threads & Tags
Similar threads

  1. Please help! User-Feature Manager problem
    By Robolovsky in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 07-23-2010, 10:26 PM
  2. Potential Cpanel security risk?
    By Frankc in forum Security
    Replies: 8
    Last Post: 01-22-2010, 11:35 AM
  3. Possible Security Risk ???
    By aisagtr in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-21-2007, 01:14 PM
  4. SECURITY HOLE = Disabling Feature Manager (BETA)
    By garak in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 02-01-2004, 06:31 PM
  5. Is enabling cron jobs for Cpanel a security risk?
    By silversurfer in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-29-2003, 12:58 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube