Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Sep 2009
    Posts
    8

    Default How come my WHM was accessed using root by one who doesn't have password?

    My WHM has been accessed using root by our branch office in other country, they only have FTP's account and password, there's no any way for them to get root's password.

    It happend once last month, and i already change root's password.

    But my WHM sent an e-mail of WHM root access alert just few minutes ago.

    Is there any possible for them to access WHM with their ftp password or what?


    our branch office is using a different ip from us, and we don't have any VPN between us.
    Last edited by frankhsu; 12-16-2009 at 02:18 AM.

  2. #2
    Member
    Join Date
    Jun 2006
    Posts
    146

    Default

    Quote Originally Posted by frankhsu View Post
    My WHM has been accessed using root by our branch office in other country, they only have FTP's account and password, there's no any way for them to get root's password.

    It happend once last month, and i already change root's password.

    But my WHM sent an e-mail of WHM root access alert just few minutes ago.

    Is there any possible for them to access WHM with their ftp password or what?
    There can be 2 things from what Ive observed:

    1. You have a cached WHM where you didnt log out and your branch office was able to access the cached session
    2. I observe that when one IP has successfully logged in to WHM and then an attempt to log in using the same IP was made even if it is not successful, WHM sends out an email that it has logged in the server as root. I dont know why such that so to check if they were really able to log in to the server, check your logs.

  3. #3
    cPanel Quality Assurance Analyst cPanelDon's Avatar
    Join Date
    Nov 2008
    Location
    Houston, Texas, U.S.A.
    Posts
    2,555
    cPanel/Enkompass Access Level

    DataCenter Provider

    Lightbulb

    WHM does not send out an e-mail upon someone logging-in; the e-mail would have been generated by a non-stock modification or third-party software.

    I recommend checking the following two log files and cross-referencing similar entries (e.g., those with a matching IP address) to help determine specific information about the login attempts and what, if anything, was accessed beyond the attempted login:
    Code:
    /usr/local/cpanel/logs/access_log
    /usr/local/cpanel/logs/login_log
    If using cPHulk the following log file may also be checked:
    Code:
    /usr/local/cpanel/logs/cphulkd.log

Similar Threads & Tags
Similar threads

  1. possible to change WHM root indepdently from server root password
    By jfall123 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 01-12-2011, 11:53 AM
  2. Modify password doesn't work in WHM.
    By Nick57 in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 08-09-2008, 07:29 PM
  3. How to reset WHM root password
    By devitnow in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-21-2008, 10:25 AM
  4. Blank page - and doesn't accept my root password.
    By UberSkilled in forum Data Protection
    Replies: 4
    Last Post: 03-10-2006, 12:31 PM
  5. Root whm mysql phpmyadmin (doesn't work)
    By thejonno in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-07-2005, 05:25 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube