Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    EWD
    EWD is offline
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Aug 2003
    Location
    NY
    Posts
    164

    Default insecure cookie(port 2083) PCI failure

    Here are the latest failures:

    2083 - Missing Secure Attribute in an Encrypted Session (SSL) Cookie - The application sets a cookie over a secure channel without using the "secure" attribute. RFC states that if the cookie does not have the secure attribute assigned to it, then the cookie can be passed to the server by the client over non-secure channels (http). Using this attack, an attacker may be able to intercept this cookie, over the non-secure channel, and use it for a session hijacking attack. - It is best business practice that any cookies that are sent (set-cookie) over an SSL connection to explicitly state secure on them.

    2083 - Potentially Sensitive Information Missing Secure Attribute in an Encrypted Session (SSL) Cookie - The application sets a cookie over a secure channel without using the "secure" attribute. RFC states that if the cookie does not have the secure attribute assigned to it, then the cookie can be passed to the server by the client over non-secure channels (http). Using this attack, an attacker may be able to intercept this cookie, over the non-secure channel, and use it for a session hijacking attack. The information that was sent was flagged as being potentially sensitive. Potentially sensitive information could be session tokens, user id's, or passwords. - It is best business practice that any cookies that are sent (set-cookie) over an SSL connection to explicitly state secure on them. Speak with your web developer to have them enable the secure attribute on cookies sent over secure connections.
    Emerson

  2. #2
    EWD
    EWD is offline
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Aug 2003
    Location
    NY
    Posts
    164

    Default

    Any ideas on this issue?

    Thanks
    Emerson

  3. #3
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,788
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by EWD View Post
    Any ideas on this issue?

    Thanks
    Full cPanel version number please.

  4. #4
    EWD
    EWD is offline
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Aug 2003
    Location
    NY
    Posts
    164

    Default

    Sorry cpanelkenneth

    Original report was running on cPanel 11.24.0-C30789
    Upgraded today to cPanel 11.24.0-C30898 and the issue is still present.

    Thanks
    Emerson

  5. #5
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,788
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by EWD View Post
    Sorry cpanelkenneth

    Original report was running on cPanel 11.24.0-C30789
    Upgraded today to cPanel 11.24.0-C30898 and the issue is still present.

    Thanks
    Thank you. I'll pass this along to the developers.

Similar Threads & Tags
Similar threads

  1. Irresolvable PCI scan failure???
    By jols in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 10-13-2010, 04:37 PM
  2. Unresolvable PCI scan failure?
    By chartierpw in forum Enkompass Discussions
    Replies: 5
    Last Post: 10-09-2010, 04:33 AM
  3. Login via Port 2083
    By Sofiot in forum Diskussion auf Deutsch
    Replies: 1
    Last Post: 08-28-2009, 05:34 PM
  4. PCI: Weak Supported Ssl Ciphers Suites on 465, 993, 995, 2083, 2087, 2096
    By rpertiet in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 10-22-2008, 02:03 PM
  5. DNSONLY and WHM on port 2083
    By Wouter in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 08-23-2005, 06:10 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube