Community Forums
Connect with us on LinkedIn
Closed Thread
Results 1 to 2 of 2
  1. #1
    Member
    Join Date
    May 2005
    Posts
    16

    Exclamation Cpanel Build 10.4.0-EDGE 254

    Hello!
    http://www.ihsteam.com/download/video/cpbug.swf
    Please explain this problem?

    Thank you.

    http://www.securitylab.ru/56471.html
    ---
    General info :
    vuln application : Cpanel Build 10.4.0-EDGE 254
    vender : www.cpanel.net
    risk : Medium
    access : to all the domains hosted
    original advisory : http://www.ihsteam.com/cms/modules/m...sit.php?lid=40
    Details :
    scenario :
    you are admin of a big hosting company , one of your customers wanted 10 mb hosting ,
    ok ah you are at home but how the hell he got the phone number anyway !
    you login to your cpanel as reseller you creat his account , creat the plan
    you USE your reseller passwd for him after the job is finished you change the
    password to urgonnohackme ! tomorrow you go to work , happy morning it is .
    but when you here that your 10000 customer sites had been defaced it completely changes
    to a terrific morning .
    also if a normal cpanel user change the pass to root by chance he wont know but
    when he change his passwd again he see all the domains listed for him !!!
    a sample movie created about how the vuln could be used :
    http://www.ihsteam.com/cms/modules/m...sit.php?lid=41
    timeline :
    vender not contacted because of the great care venders give us !
    08 august 2005 : public disclosure

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    This is already being discussed:
    http://forums.cpanel.net/showthread.php?t=42408
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. Anyone got the latest Edge build?
    By Underbelly in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 09-19-2008, 11:57 AM
  2. FTP not working - Edge build
    By 4hosted in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 04-12-2008, 09:56 AM
  3. Edge build changelog ?
    By katmai in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 02-22-2007, 01:39 AM
  4. Edge 8.5.4 build 61
    By jackal in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 11-14-2003, 08:31 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube