#1 (permalink)  
Old 09-12-2002, 11:38 AM
Registered User
 
Join Date: Sep 2001
Posts: 187
H2Hosting.com
Cpanel "domain parking" FRAUD

The problem:

1) For example, I host 2 domains for 2 customers - domain_1.com and domain_2.com

2) 1st customet who own first domain can park sub.domain_2.com (!!! - subdomain of second domain) on top of his own domain_1.com

If i own &pornogirls.com& i can park &support.hostingcompany.com& on top of &pornogirl.com& even if i do not own &hostingcompany.com& domain

ha ha ha
__________________
Alex Andreyev,
http://www.WHost.INFO - NEW web hosting directory.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 09-12-2002, 02:50 PM
Registered User
 
Join Date: Jul 2002
Posts: 25
webdave
hostingcompany.com's nameservers would have to point to your server for the parking to work.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 09-12-2002, 03:38 PM
Registered User
 
Join Date: Sep 2001
Posts: 187
H2Hosting.com
I know. In this example, both domains are on the same server.
__________________
Alex Andreyev,
http://www.WHost.INFO - NEW web hosting directory.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 09-12-2002, 11:56 PM
Registered User
 
Join Date: Aug 2001
Posts: 707
moronhead is on a distinguished road
H2, are you saying that support.hostingcompany.com is redirecting to pornogirls.com and hostingcompany.com's owner knows nothing about it?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 09-13-2002, 12:32 AM
Registered User
 
Join Date: Oct 2001
Posts: 648
Marty is on a distinguished road
That is exactly what he is saying. I can park a sub of any domain on the server to my domain whether I own the domain that I made the sub of or not.
__________________
Marty Hoskins
TLC Web Enterprises
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 09-13-2002, 12:39 AM
Registered User
 
Join Date: May 2002
Posts: 152
ecoutez
Eek, that's very scary!

The implications of this are seriously frightening. I don't want to spell out the possibilities, but those subdomain names could be really bad... like payments. or billing. or order. etc. And for those of us hosting our own websites on CPanel boxes with our clients... oh man... I'm gonna need a Valium for something.

- Jason
__________________
Ecoutez! Ltd.
www.ecoutez.com
Our new Theme: www.MaxPanel.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 09-13-2002, 02:00 AM
Registered User
 
Join Date: Sep 2001
Posts: 187
H2Hosting.com
yes, this is not good and should be fixed asap.
__________________
Alex Andreyev,
http://www.WHost.INFO - NEW web hosting directory.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 09-13-2002, 02:00 AM
Registered User
 
Join Date: Sep 2001
Posts: 187
H2Hosting.com
yes, this is not good and should be fixed asap.
__________________
Alex Andreyev,
http://www.WHost.INFO - NEW web hosting directory.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 09-13-2002, 10:22 AM
Registered User
 
Join Date: Sep 2002
Location: Aussie Land
Posts: 7
cbservers
Zoneedit

If you use zoneedit.com as your nameservers you can direct only your primary domain to your servers
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 09-13-2002, 01:40 PM
Registered User
 
Join Date: Sep 2001
Posts: 187
H2Hosting.com
[quote:44eb4b26c0][i:44eb4b26c0]Originally posted by cbservers[/i:44eb4b26c0]
If you use zoneedit.com as your nameservers you can direct only your primary domain to your servers[/quote:44eb4b26c0]

And what?
If you host &1000 customer's sites there is no reason to use zoneedit as DNS provider.

Why not to use another control panel?
We use Cpanel and we pay for it, so ALL bugs should be fixed asap.
__________________
Alex Andreyev,
http://www.WHost.INFO - NEW web hosting directory.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 09-13-2002, 06:06 PM
Registered User
 
Join Date: Aug 2001
Posts: 707
moronhead is on a distinguished road
Can someone tell me if there's a difference between setting up a parked domain in WHM and setting it up inside Cpanel?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12 (permalink)  
Old 09-14-2002, 12:11 AM
bdraco
Guest
 
Posts: n/a
this should be resolved in build 40. In the future, please submit a support ticket rather then posting here about potential security problems.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #13 (permalink)  
Old 09-16-2002, 11:15 AM
Registered User
 
Join Date: Sep 2002
Posts: 135
YukFoo is on a distinguished road
I agree, security issues shouldn't be posted in the forum. Just my 2 cents.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 08:38 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc