Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    Nov 2004
    Posts
    50

    Default Possible Security Flaw

    Hi,

    Today in cPanel I found out that the link it gives you to click to download today's backup can easily get someone elses files. All you do is change the domain in the link and you have access to backups of anyone on that server. Is there a setting to fix it? Or is that something that the cPanel staff aren't aware of.

    Thanks,
    Derek

  2. #2
    Member
    Join Date
    Oct 2004
    Location
    New Jersey, USA
    Posts
    160

    Default

    That's QUITE bad accutally - CPanel any word on this? They will probably ask you to add to Bugzilla, regardless that it's their error
    -Kris
    HostMerit
    'Web Hosting on Your Terms'

  3. #3
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Well, that's what bugzilla is for, to list bugs. You should email security@cpanel.net immediately if you believe you've found a security bug.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  4. #4
    Member
    Join Date
    Oct 2004
    Posts
    22

    Exclamation cPanel BUG - IMPORTANT

    hello,

    i was doing backups in my system and i found a bug. any user who is logged in can get another users backup. ex.

    any user logs in to their cPanel account. if they go to https://1.2.3.4:2083/getbackup/backu...29-2005.tar.gz

    they can get the backup of domainname.tld. this can be done for ALL Accounts.

  5. #5
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    You need to email such issues to security@cpanel.net and log it in bugzilla as posting here will not bring it to cPanel's attention.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  6. #6
    cPanel Staff
    Join Date
    Dec 2001
    Location
    Houston, TX
    Posts
    1,846

    Default

    Hello,

    Are you referring to a URL such as this :
    https://host.server.tld:2083/getback...30-2005.tar.gz
    ?
    If so, you are still getting your own backup, you are just downloading it under a different name.

    Thanks,
    Darren

  7. #7
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    False error, you can put any word there and it will still be the backup of the correct domain.
    Regards,
    David
    Forum Moderator

Similar Threads & Tags
Similar threads

  1. Security Flaw with email in cpanel?
    By Secmas in forum Security
    Replies: 6
    Last Post: 04-14-2010, 04:05 PM
  2. dns clustering security flaw
    By optize in forum cPanel and WHM Discussions
    Replies: 25
    Last Post: 01-15-2010, 08:42 PM
  3. DNS Security Flaw
    By compunet2 in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-10-2008, 09:11 AM
  4. ZLib Security Flaw
    By trparky in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 07-07-2005, 09:21 AM
  5. phpMyAdmin Security Flaw
    By PeteC in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 02-05-2004, 03:21 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube