Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Registered User
    Join Date
    Mar 2006
    Posts
    2

    Default User password the same as root issue

    Hi all,

    I have Cpanel installed on a VPS. Yesterday I created a new account which used the same password as the rooter user. When I then logged into the account, I had the drop down at the top of the homepage showing all accounts on the server.

    I changed the password for the user, logged out and back in again, and everything was back to normal.

    I thought this was strange and wondered if this might be a bug?

    I should probably also notify my hosting company.

  2. #2
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,117
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Fairly sure that's a feature. Easy fix: don't have the passwords the same. :P

  3. #3
    Registered User
    Join Date
    Mar 2006
    Posts
    2

    Default

    Quote Originally Posted by brianoz View Post
    Fairly sure that's a feature. Easy fix: don't have the passwords the same. :P
    a feature, surely its a security risk?

  4. #4
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,117
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    If you think about it, you'll realize it's not a security risk. Simply use a secure password for root and you're fine.

  5. #5
    Member dansgalaxy's Avatar
    Join Date
    Jan 2007
    Location
    Reading, UK
    Posts
    91
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    I see your thoughts of what if a user happens to use the same password as root
    which is why root passwords should really be VERY long and VERY complex

    like R545VD!sdcdm)(k??>

  6. #6
    Member
    Join Date
    Apr 2007
    Location
    Bakersfield, California
    Posts
    270

    Default

    This has been a feature of cPanel for awhile iirc, however you can disable it in WHM under Tweak Settings. I believe the setting is called "disable login to accounts using root/reseller password" or something like that.


    Most of the time I leave it enabled though because at times it is nice to not have to ask for a user's password, or reset it. My root passwords are normally 64 characters though, so I don't worry about someone having the same pass as it is highly unlikely.
    Last edited by Voltar; 12-18-2008 at 01:52 PM. Reason: Typo...

  7. #7
    Member dansgalaxy's Avatar
    Join Date
    Jan 2007
    Location
    Reading, UK
    Posts
    91
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by Voltar View Post
    This has been a feature of cPanel for awhile iirc, however you can disable it in WHM under Tweak Settings. I believe the setting is called "disable login to accounts using root/reseller password" or something like that.


    Most of the time I leave it enabled though because at times it is nice to not have to ask for a user's password, or reset it. My root passwords are normally 64 characters though, so I don't worry about someone having the same pass as it is highly unlikely.

    my point exactly

Similar Threads & Tags
Similar threads

  1. possible to change WHM root indepdently from server root password
    By jfall123 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 01-12-2011, 11:53 AM
  2. Issue with Changing Mail User Password
    By keithc in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 10-18-2007, 09:47 AM
  3. cpanel bug / Get root access with root password
    By majidnt in forum cPanel and WHM Discussions
    Replies: 19
    Last Post: 08-24-2005, 11:12 AM
  4. Password - User issue (maybe alias issue)
    By Curt in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 09-20-2002, 10:08 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube