Results 1 to 11 of 11

Thread: Why is this done?

  1. #1
    Member
    Join Date
    Jul 2003
    Posts
    6

    Thumbs down Why is this done?

    Sorry if this has been posted elsewhere before..Search returned nothing.

    I was just browsing throug hmy CPanel control panel when I went into the "FTP Account Maintenance" section.

    To my shock, my clear text password is in the URL that links to the FTP download of the logfiles!

    ftp://myaccount_logsassword@ftp.myserver/myserver.com

    Will this be changed in the future?

  2. #2
    Member
    Join Date
    Oct 2003
    Posts
    1,020

    Default

    When using standard FTP, your password is transmitted in plain text. You need to know your password to login to your cpanel right? So what is the big deal?

    I agree that unamew combinations should not be sent via URL links under any circumstances and I understand your concern that your password is "on display" for anyone that might be walking by, but FTP is a security issue anyway you slice it.

  3. #3
    Member
    Join Date
    May 2004
    Location
    USA
    Posts
    413
    cPanel/WHM Access Level

    Root Administrator

    Default

    Originally posted by SarcNBit
    When using standard FTP, your password is transmitted in plain text. You need to know your password to login to your cpanel right? So what is the big deal?

    I agree that unamew combinations should not be sent via URL links under any circumstances and I understand your concern that your password is "on display" for anyone that might be walking by, but FTP is a security issue anyway you slice it.
    But, according to cpanel, all our passwords are stored as a 1-way hash, so how does cpanel know our password? It must be stored as plain-text on the server!!! This is VERY BAD

  4. #4
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,496

    Default

    n/m
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  5. #5
    Member
    Join Date
    May 2004
    Location
    USA
    Posts
    413
    cPanel/WHM Access Level

    Root Administrator

    Default

    With the password being embedded into the links, that causes the password to be saved in the Internet Explorer history. This is different than sniffing the password when you type it in...

  6. #6
    Member
    Join Date
    May 2004
    Location
    USA
    Posts
    413
    cPanel/WHM Access Level

    Root Administrator

    Default

    Originally posted by thaphantom
    I believe it is stored in a cookie, when u log out or close the browser the cookie gets eaten byt the cookiemonster
    That is only if you click on File -> Login As...

    CPanel is embedding it into the url, which is added to the history.

  7. #7
    Member
    Join Date
    May 2004
    Location
    USA
    Posts
    413
    cPanel/WHM Access Level

    Root Administrator

    Default

    Originally posted by thaphantom
    only if you use the ftp logs. which opens an ftp conection.
    That's exactly what I have been talking about...

  8. #8
    Member
    Join Date
    Oct 2003
    Posts
    1,020

    Default

    Originally posted by jandafields
    With the password being embedded into the links, that causes the password to be saved in the Internet Explorer history.
    I thought IE was no longer supporting that method.

  9. #9
    Member
    Join Date
    May 2004
    Location
    USA
    Posts
    413
    cPanel/WHM Access Level

    Root Administrator

    Default

    Actually, I read that earlier today somewhere (IE not allowing that syntax anymore). Another good reason to get rid of the password in the links (just let IE prompt you for it)...

  10. #10
    Member
    Join Date
    Nov 2002
    Posts
    24

    Default

    Just another reason why you should log in to cpanel using the secure connection

  11. #11
    Member
    Join Date
    Jan 2004
    Location
    Planet Earth
    Posts
    6

    Default

    Why not use a free piece of software that is more reliable than Microshaft? FileZilla is free, works like a champ and is a hell of a lot more stable than the crap that MS puts out there.
    Brian Hawver
    RockSTAR Solutions, LLC

    ----

    Get hosting for as low as $5/mo.
    For a limited time...1GB of space and 10GB of bandwidth for $10/mo.

    http://www.rockstarsolutions.com