Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    Sep 2003
    Posts
    5

    Arrow BULK Password Reset possible - hacked

    I have close to 100 accounts on one Cpanel account. Is it possible to Bulk Password Modification all accounts at ONCE?

    I don't actually need to know the new password. If I do need to FTP to the site, I will manually change the FTP for the one account.

    I want to constantly change the Passwords to defeat any possible hacker attempts (gumblar/malware virus).

  2. #2
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    10,720
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by gariben View Post
    I have close to 100 accounts on one Cpanel account. Is it possible to Bulk Password Modification all accounts at ONCE?

    I don't actually need to know the new password. If I do need to FTP to the site, I will manually change the FTP for the one account.

    I want to constantly change the Passwords to defeat any possible hacker attempts (gumblar/malware virus).
    You could build a script that uses our APIs to perform the bulk password modification. However, no such feature is built into the cPanel user interface at this time.

    Keep in mind, FTP is an inherently insecure protocol since usernames and passwords are always sent in plain text (which anyone can read). I recommend you and your colleagues switch to FTP over SSL/TLS (FTPS) instead. Many FTP clients support this and it's often just a matter of switching a setting from "FTP" to "FTPS" in the FTP client.

    With FTPS, everything is the same except now your username and password is encrypted when it is sent to the server. This means it is harder for others to snoop on your traffic to grab your passwords (not just malware).

    Of course, it is prudent to ensure systems that are connecting to your site to upload content are clear of malware.

    Additionally, if you find yourself with many FTP accounts that are not being used frequently, you may want to delete those unused FTP accounts.

  3. #3
    Member
    Join Date
    Jan 2005
    Location
    London, UK
    Posts
    187

    Default

    Is there any way we can disable standard FTP on cPanel servers, and only allow SFTP or FTPS?

    Thanks,

    - Vince

  4. #4
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    10,720
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by mambovince View Post
    Is there any way we can disable standard FTP on cPanel servers, and only allow SFTP or FTPS?

    Thanks,

    - Vince
    Unfortunately, not at this time.

  5. #5
    Member sawbuck's Avatar
    Join Date
    Jan 2004
    Posts
    1,310
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    David,

    With apologies to gariben for further hijacking this thread, can you clarify the following?

    Using pure-ftpd in WHM > Ftp Server Config, the option to "Require" TLS Encryption Support should encrypt the password information but the protocol falls back from Prot P to Prot C (unencrypted data channel) after connection. This should effectively disable standard FTP connections and only allow FTPS.

    My understanding is the forth coming cPanel 11.25 will include the option to enforce Prot P (TLS 3 - encrypted comm and data channels).

    Another option seems to be disabling pure-ftpd to only allow SFTP using the SSH port. Dreamweaver for instance has SFTP capability.

  6. #6
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    10,720
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by sawbuck View Post
    David,

    With apologies to gariben for further hijacking this thread, can you clarify the following?

    Using pure-ftpd in WHM > Ftp Server Config, the option to "Require" TLS Encryption Support should encrypt the password information but the protocol falls back from Prot P to Prot C (unencrypted data channel) after connection. This should effectively disable standard FTP connections and only allow FTPS.

    My understanding is the forth coming cPanel 11.25 will include the option to enforce Prot P (TLS 3 - encrypted comm and data channels).

    Another option seems to be disabling pure-ftpd to only allow SFTP using the SSH port. Dreamweaver for instance has SFTP capability.
    Thanks for pointing out that configuration setting to me. I must have overlooked it when going through the .conf files.

    I believe requiring encryption is what you are looking for.

    Regarding using only SFTP, keep in mind that FTP accounts you have created do not work with SFTP, only FTP and FTPS. Only your cPanel credentials will work with SFTP. I know our UI says otherwise, and that is a bug that is being resolved (Case 26282)

  7. #7
    Member sawbuck's Avatar
    Join Date
    Jan 2004
    Posts
    1,310
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by cPanelDavidG View Post
    Only your cPanel credentials will work with SFTP. I know our UI says otherwise, and that is a bug that is being resolved (Case 26282)
    Thanks David for pointing that out. So far in testing had only used cPanel credentials.

Similar Threads & Tags
Similar threads

  1. Force password reset failing - The new password fields don't match
    By SynAsha in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 06-03-2011, 08:11 PM
  2. How does the password aging/force password reset work?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 12-28-2010, 09:32 AM
  3. Cannot reset password
    By linux.newbie in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-28-2008, 09:26 AM
  4. Replies: 5
    Last Post: 02-07-2004, 04:21 PM
Tags for this Thread
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube