Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Nov 2002
    Posts
    60

    Default Password retrieval

    Is there an easy way to be able to retrieve a customer password from the WHM interface? I used to have a plesk server with a utility from 4psa that would grab all sorts of nice information for you, including retrieval of customer passwords, etc. That allows you to provide the customer with that info, should they request it. The only thing I can see in WHM is the ability to change the password.

  2. #2
    Member
    Join Date
    Jun 2003
    Posts
    177

    Default

    I do not think it is possible to retrieve passwords at all, MD5 encryption
    I would not want this to be possible anyway, if you ever have a server hacked, last thing you need is everyones passwords released

  3. #3
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    It isn't possible, they're one-way encrypted. The only way you could get it would be to brute-force the shadow file and that is no guarantee and can take hours/days/months/years.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  4. #4
    Member
    Join Date
    Nov 2002
    Posts
    60

    Default

    I guess that shows a little bit of a security hole in plesk then. 4psa notifications can retrieve every password stored that is used by plesk. if someone can admin login into your psa interface your screwed.

  5. #5
    Member
    Join Date
    Jun 2003
    Posts
    177

    Default

    Quote Originally Posted by rmackay View Post
    I guess that shows a little bit of a security hole in plesk then. 4psa notifications can retrieve every password stored that is used by plesk. if someone can admin login into your psa interface your screwed.
    Exactly right, MD5 is a one way hash and can not be decrypted.

    I have never used Plesk but I have a tough time with the fact that the password files are accessible. As a Windows Network Administrator, I would be not very happy about it. I do not want/need/desire access to user passwords. Accountability to network or account access is a real "CYA" thing.

Similar Threads & Tags
Similar threads

  1. POP3 password retrieval / mail monitoring
    By m175400 in forum E-mail Discussions
    Replies: 0
    Last Post: 02-08-2010, 05:31 PM
  2. Password Retrieval options for customers
    By tonedoggydogg in forum cPanel and WHM Discussions
    Replies: 12
    Last Post: 07-07-2008, 10:12 PM
  3. Password retrieval
    By drewh01 in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 07-06-2007, 04:44 PM
  4. Account password retrieval
    By drewh01 in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-07-2007, 01:34 PM
  5. Protected Directory Password Retrieval
    By MrHWD in forum Database Discussions
    Replies: 1
    Last Post: 03-22-2007, 08:56 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube