Over the weekend, I received two messages from cPHulk that said, "Root was logged into pure-ftpd using following authentication service: system". Each was from a different country and different IP address.
This seemed strange, because in my WHM "FTP Server Configuration" the option "Allow Logins with Root Password" was set to "No" (disabled). Besides that, we use a strong password that would be difficult to guess, especially with cPHulk limiting all brute-force attempts.
I contacted my host, InMotion Hosting, and they looked into it. They said, "I'm seeing that there were attempted logins using the root user but no successful logins." I asked if it was a bug then, and they said, "I would have to say that would be a bug."
So ... my reason for posting here is to see if there is a known issue with this, if there is anything I should do to verify or confirm the issue, and how I might go about submitting a bug report. (I Googled for it, but the pages that came up seemed to indicate that the bug report links were for the license holder, which I guess would be InMotion Hosting in this case.)
This seemed strange, because in my WHM "FTP Server Configuration" the option "Allow Logins with Root Password" was set to "No" (disabled). Besides that, we use a strong password that would be difficult to guess, especially with cPHulk limiting all brute-force attempts.
I contacted my host, InMotion Hosting, and they looked into it. They said, "I'm seeing that there were attempted logins using the root user but no successful logins." I asked if it was a bug then, and they said, "I would have to say that would be a bug."
So ... my reason for posting here is to see if there is a known issue with this, if there is anything I should do to verify or confirm the issue, and how I might go about submitting a bug report. (I Googled for it, but the pages that came up seemed to indicate that the bug report links were for the license holder, which I guess would be InMotion Hosting in this case.)