Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Page 2 of 2 FirstFirst 1 2
Results 16 to 20 of 20
  1. #16
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,093
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by brianoz
    I guess currently that cpanel checks for a root password before checking for the user password and I'm suggesting a reversal of order in the checks.
    This would be a good, and small, change that would eliminate the security complaint entirely. That is, check for the user password first, and use it as that if it matches, regardless of whether the password matches the root password as well.

  2. #17
    Registered User
    Join Date
    Jul 2005
    Posts
    4

    Default It is a bug

    Quote Originally Posted by brianoz
    If you guess the root password, you have access to everything on the box. If I guess *your* password, I've got access to everything in your account. That's just the way operating systems work.

    In the example of the bug, the person was logged in as a normal user, with the normal user password, which is the same as the root and had access to other accounts. This is NOT the way operating systems work, if your normal user has the same password as root, they do not get root access. Unless of course they log in as root.


    But still you have to give this user the same password as root, and I doubt any of us would actually do that


    Steve

  3. #18
    Registered User
    Join Date
    Jul 2005
    Posts
    4

    Default

    Quote Originally Posted by baileysemt
    IMO, it still keeps coming back to "use a stronger root password." It's really not cPanel's job to protect people from being stupid. If you run a server, it's your responsibility. Use a strong root password to protect it.

    Bailey
    I agree with the strong root password, make sure it's nothing simple! Actually all passwords should not be simple ever!


    IMO It comes down to a flaw in the login process!

    A user logging in as themself should not be given superuser information because his password is the the same as root!!!


    Now of course in any enviroment if they login as root/administrator/superuser and try their password they get access. But here they login and are TOLD they have the same password and given the access.

    Makes you wonder how the login system works!





    Steve
    Last edited by shulshof; 08-24-2005 at 11:21 AM.

  4. #19
    BANNED
    Join Date
    Jul 2005
    Posts
    537

    Default

    This exact thing happened to us last week. A reseller sent us an email telling us that he could see ever username from the dropdown list from his account.

    I checked it out and sure enough there is was. I emailed Cpanel and they told me this is a known bug in Edge and that we should downgrade to Stable. Once we downgraded to S the problem was resolved. So if your running Edge be careful! I can assure you that our reseller did not have our root password.

  5. #20
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Well, you can simply disable this in RELEASE/CURRENT/EDGE now as I mentioned in an earlier post if you want to. though it breaks the ability to connect to the users cPanel account, which is a pain.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. Bug with MySQL Root Password Change
    By interweb12345 in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 09-17-2008, 01:30 AM
  2. WHM Bug: Root Access Denied
    By andren in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-22-2008, 05:55 AM
  3. Changing root Password Bug
    By equens in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 01-10-2006, 10:28 AM
  4. A possible BUG that is very serious!! ROOT ACCESS
    By jpabboud in forum cPanel and WHM Discussions
    Replies: 15
    Last Post: 08-28-2004, 12:51 PM
  5. cannot access to users' CPanel with root password
    By luna in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 03-20-2004, 01:58 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube