Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 12 of 12
  1. #1
    Member
    Join Date
    Sep 2002
    Posts
    30

    Exclamation --- ALERT: Open whole for hackers in CPanel ---

    There is a whole in Cpanel that allows hacker to take FULL CONTROL over ANY account on your server.
    More still to come, I'am checking this with few ISP's.

    WHY DIDN'T ANYONE FROM CPANEL TOLD US ABOUT THIS ???
    There is a BIG - HUGE security whole in Cpanel and no one didn't say anything about it ??
    come on CPanel support where are you ??

  2. #2
    Member
    Join Date
    Sep 2002
    Posts
    30

    Default

    I'am asking CPanel support I need to know is this bug fixed 100% in new CPanel 6, as stated "maybe" is not good for me, I need to know for A FACT is version 6 completey off this security risk ?

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Aug 2001
    Posts
    445

    Default

    What hole would that be? There's no shortage of people who take delight in pointing out security issues with cPanel and then point to something else as being superior, despite the fact that there are holes to be found in everything. There are also indications in WHM news about issues that crop up with something in cPanel and their resolutions, even if they don't always check their spelling first:

    "All traces of openwebmail have been elimiated as it has multiple secuirty issues."
    "Fix a large secuirty hole in guestbook.cgi"

    Much better than our old Alabanza days where we reported bugs and then waited...and waited...and waited....
    Annette
    Hosting Matters, Inc.
    http://www.hostmatters.com

  4. #4
    Member
    Join Date
    Oct 2002
    Posts
    35

    Default

    btw..it's spelt H-O-L-E.

  5. #5
    Member
    Join Date
    Feb 2002
    Location
    UK
    Posts
    461

    Default

    Originally posted by iisnet
    btw..it's spelt H-O-L-E.
    lol would you mind tellings us all what this huge hole is then?

  6. #6
    Member
    Join Date
    Mar 2002
    Location
    Alberta, Canada
    Posts
    1,509

    Default

    I wonder if the whole "hole" security thing is about the HOT bug, common with so many systems. It's a known fact that it works on "any" operating system in any Country at any time of the day. The HOT bug has been around as long as there have been Computers, the possibility of eliminating it seems to be about NIL!

    Hackers, Crackers, and Whackers have long known about the HOT bug and it seems only now, most IT depts. are cluing in to it.

    Mwwwhahaha...
    Be afraid, be very afraid.
    Helping people Host, Create, and Maintain their Web Site
    Also providing Server Admin Services - setup / troubleshooting

    http://potentproducts.com/

  7. #7
    Member
    Join Date
    Mar 2002
    Location
    Alberta, Canada
    Posts
    1,509

    Default

    Whoops... got you all excited and forgot to specifiy what the HOT bug is.

    It's a Human On Telephone of course.
    Helping people Host, Create, and Maintain their Web Site
    Also providing Server Admin Services - setup / troubleshooting

    http://potentproducts.com/

  8. #8
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    Originally posted by Website Rob
    Whoops... got you all excited and forgot to specifiy what the HOT bug is.

    It's a Human On Telephone of course.

    Sweet!!! I like that one...
    Regards,
    David
    Forum Moderator

  9. #9
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default

    This is a semi-old problem, A security group found the vuln and i was subscribed to it. I tested both holes. The guestbook vuln was true, and the openwebmail one was not. Openwebmail was still removed because it's not used. I informed nick of these the "hole" right away and he fixed them. I think he actually might have had the guestbook hole fixed before. anyway, upgrading to build 6.0.x fix's the problems.
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

  10. #10
    Member
    Join Date
    Feb 2003
    Posts
    190

    Default Re: --- ALERT: Open whole for hackers in CPanel ---

    Originally posted by DianaL
    There is a whole in Cpanel that allows hacker to take FULL CONTROL over ANY account on your server.
    More still to come, I'am checking this with few ISP's.

    WHY DIDN'T ANYONE FROM CPANEL TOLD US ABOUT THIS ???
    There is a BIG - HUGE security whole in Cpanel and no one didn't say anything about it ??
    come on CPanel support where are you ??
    Quit being a dumbass. Fixing it involved changing a couple of permissions...

  11. #11
    Member
    Join Date
    Apr 2002
    Posts
    54

    Default

    What is this hole you are talking about? Care to be a bit more specific?

    Is it the guestbook which was already patched?

    Inquiring minds would like to know

  12. #12
    Member
    Join Date
    May 2002
    Posts
    161

    Default

    oh...nevermind..post edited

Similar Threads & Tags
Similar threads

  1. Phishing Alert: cPanel
    By cPanelDavidG in forum cPanel Announcements
    Replies: 1
    Last Post: 01-14-2011, 01:31 PM
  2. Hackers can gain access to Cpanel
    By driverC in forum cPanel and WHM Discussions
    Replies: 15
    Last Post: 05-03-2008, 02:56 PM
  3. App for Cpanel to prevent hackers/spammers from using my server to send spam?
    By listenmirndt in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-29-2007, 10:26 AM
  4. Instant Alert for cpanel?
    By budway in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 07-26-2006, 03:52 AM
  5. How to close open backdoors for hackers?
    By pingo in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 09-12-2003, 03:56 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube