Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member tuxfan's Avatar
    Join Date
    Oct 2006
    Location
    between chair and keyboard
    Posts
    11

    Default cPanel login, security issue

    If a user goes to hisdomain.com/cpanel, he is prompted for a username and a password. But simply entering a password takes him into cPanel, even if the username is left blank.

    Does this not reduce the security by 50%?

    I always try to make a somewhat un-common usernames for my cPanel accounts. But that seems useless after I discovered this bug (or feature?). Any solution to this?

  2. #2
    Member
    Join Date
    Jun 2005
    Posts
    159

    Default

    After a few us of bitched long enough about this stupid "feature" it has finally been dealt with, just not in STABLE yet, perhaps not in RELASE as well. It's not a bug, hard to believe I know.

  3. #3
    Member
    Join Date
    Mar 2006
    Posts
    1,215

    Default

    Quote Originally Posted by tuxfan
    If a user goes to hisdomain.com/cpanel, he is prompted for a username and a password. But simply entering a password takes him into cPanel, even if the username is left blank.

    Does this not reduce the security by 50%?

    I always try to make a somewhat un-common usernames for my cPanel accounts. But that seems useless after I discovered this bug (or feature?). Any solution to this?
    To get around this for now:

    tweak settings > whm > system
    check the two boxes:
    Always redirect users to the ssl/tls ports when visiting /cpanel, /webmail, etc.
    When visiting /cpanel or /whm or /webmail with ssl redirect to the servers hostname.

    When you are forced to the login from the host name location, cpanel is no longer associated with a users name, thus they have to know what user name is as well as the password.

    And of course for added security, you can force clients to use something other than the assumed user name that cpanel generates from the domain name.
    If you have resellers, then oh well... their host provider domain will be revealed.

Similar Threads & Tags
Similar threads

  1. Potential security issue with cPanel.
    By jols in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 12-03-2010, 01:27 AM
  2. cPanel 11.25 Security Tokens issue
    By sven4o in forum Security
    Replies: 10
    Last Post: 07-30-2010, 02:12 PM
  3. Major Security Issue In Cpanel
    By ukhost4u in forum cPanel and WHM Discussions
    Replies: 22
    Last Post: 10-22-2006, 11:28 AM
  4. Possible cPanel security issue
    By derekg in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 01-17-2006, 06:16 PM
  5. security issue in cPanel
    By vocalist in forum cPanel and WHM Discussions
    Replies: 9
    Last Post: 09-14-2005, 05:32 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube