Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Dec 2007
    Posts
    27

    Default Securing cPanel - WHM

    Hello, I've just completed all the steps here : http://blog.cpanel.net/?p=60

    However there is still on thing that doesn't seem very secure ... :

    Logging into WHM with root user and simple password !

    It's all very well securing SSH as it recieves the most password attacks however what is the best way to secure WHM? I don't like logging into WHM with root user... Is there a way to disallow root logins on WHM giving another user the rights, or is it possible to also use RSA keys or similar for logging into WHM?

    Thanks in advance

  2. #2
    Member
    Join Date
    Feb 2003
    Location
    Aussie Land!
    Posts
    32

    Default

    Create an account say admin.com and username admin than setup that as a reseller with root pervious and problem solved

    Otherwise force WHM to redirect to the SSL location and any username/password data will be sent over 256bit SSL.

  3. #3
    Member
    Join Date
    Jun 2008
    Posts
    48

    Default

    Good solution, thank you Spirit.

  4. #4
    Member
    Join Date
    Dec 2007
    Posts
    27

    Default

    Thankyou,

    That saves me from logging in as root, but does not stop someone else from signing in as root.

    Is there a was to disallow root login to cPanel, a bit like with SSH?

  5. #5
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,165
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb

    cPHulk in Security Section of WHM can help, this can help even more:
    http://www.configserver.com/cp/csf.html

    Limiting the number of failed login attempts is a great suggestion to run with there.

Similar Threads & Tags
Similar threads

  1. Securing a new cPanel server, suExec, suPHP etc
    By Dragooon in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-19-2011, 07:53 AM
  2. Securing Apache in cPanel
    By crosswinds in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 06-19-2009, 09:05 AM
  3. Securing whm (dns-only)
    By ManuelT in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 06-10-2009, 09:03 AM
  4. Securing Cpanel Server
    By flashweb in forum cPanel and WHM Discussions
    Replies: 11
    Last Post: 06-26-2003, 03:05 PM
  5. Securing a cpanel box
    By mpope in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 01-08-2002, 03:36 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube