Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Member
    Join Date
    Sep 2002
    Posts
    64

    Default So I hear this rumor...

    Not that I believe most things that are posted at TheRegister.co.uk, there's a rumor of a security issue in WHM/Cpanel.
    http://www.theregister.co.uk/2009/08..._trinity_csrf/

    Any official word on this from Cpanel?

  2. #2
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,165
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb

    Yes. An announcement concerning this is located here.
    cPanel Security Update: CSRF (cross-site request forgery) - cPanel Inc.

  3. #3
    teh
    teh is offline
    Member
    Join Date
    Jul 2008
    Posts
    5

    Default

    Any cpanel security advisory/announcement mailing list that one can subscribe to stay informed?

  4. #4
    Member Data 1's Avatar
    Join Date
    May 2008
    Posts
    102

    Default

    Quote Originally Posted by Infopro View Post
    Yes. An announcement concerning this is located here.
    cPanel Security Update: CSRF (cross-site request forgery) - cPanel Inc.

    It seems like the odds of this happening would be so small that you would have a better chance of winning the lottery twice in one week. If this is the worst exploit we have to worry about I feel very safe.

  5. #5
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,165
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb

    This is the root page for that security blog. Security - cPanel Inc. where you'll find a block on the left to sign up for the News List.

  6. #6
    teh
    teh is offline
    Member
    Join Date
    Jul 2008
    Posts
    5

    Default

    @Infopro:

    I don't see the recent posts on Security - cPanel Inc. in the news mailing list archive: News Private Archives Authentication.

    I think the block on the left on the Security - cPanel Inc. page doesn't subscribe for the same list. We need a mailing list or an RSS feed with cpanel's security advisories as posted on Security - cPanel Inc..

    thanks upfront.

  7. #7
    cPanel Staff mario-cPanel's Avatar
    Join Date
    Oct 2007
    Location
    Houston, Texas, United States
    Posts
    59
    cPanel/Enkompass Access Level

    Website Owner

    Default

    Quote Originally Posted by teh View Post
    @Infopro:

    I don't see the recent posts on Security - cPanel Inc. in the news mailing list archive: News Private Archives Authentication.

    I think the block on the left on the Security - cPanel Inc. page doesn't subscribe for the same list. We need a mailing list or an RSS feed with cpanel's security advisories as posted on Security - cPanel Inc..

    thanks upfront.
    teh we appreciate the feedback.

    Over the next few weeks we will be working on a re-org of the forums that will include a thread specifically about important information that will be provided solely by cPanel directly. You will be able to subscribe and RSS feed from this thread once it is online.

    In the meantime your welcome to browse News - cPanel Inc. for updates from cPanel at this time.

    Thanks again,
    Mario Rodriguez
    cPanel.net
    Strategic Partner Manager
    mario@cPanel.net
    415-894-5882 / aim: cpanelmario

  8. #8
    Member
    Join Date
    May 2005
    Location
    Auburn, CA
    Posts
    234

    Default

    Odd....I'm on the "cPanel news" mailing list (I still have the confirmation email:
    "Mailing list subscription confirmation notice for mailing list News").

    I receive monthly reminders that I'm on the list...including the news that 11.25 is now available, and yet I haven't received any security notices.

    cPanel really should offer RSS, rather than just email subscriptions.
    cPanel: Latest Release Version [11.30.*]
    PHP 5.3.8, Apache 2.2.21, MySQL 5.1.54, Perl 5.8.8, CentOS 4.9

Similar Threads & Tags
Similar threads

  1. Who would you like to hear speak?
    By ericgregory in forum cPanel Announcements
    Replies: 8
    Last Post: 08-05-2010, 10:52 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube