Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

Security bug in cPanel login

Discussion in 'Security' started by jdr, May 22, 2012.

  1. jdr

    jdr Registered

    Joined:
    May 22, 2012
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    51
    cPanel Access Level:
    Reseller Owner
    Hi,

    turns out this is probably the easiest way to report a problem...

    You have (what I'd consider) a security bug in your cPanel login system. On a reseller account (for example) if a user has the same password as the administrator then even if the user logs into their site with their username and their password (which happens to be the same as the admin) then they get logged in as the admin! = Not good!!

    James
     
  2. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    16,167
    Likes Received:
    370
    Trophy Points:
    583
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    Hi, not really. This is the proper way: http://go.cpanel.net/bugs


    I believe this thread from back in 2008 should shed some light on your post though:
    User password the same as root issue - cPanel Forums

    Or more precisely this Documentation:
    Accounts that can access a cPanel user account - cPanel Documentation

    You'll find the setting to change this located here:
    WHM > Server Configuration > Tweak Settings, System Tab, first item at top:
    Accounts that can access a cPanel user account: cPanel User Only (might be best at all times unless otherwise needed)

    Hope that helps!
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice