Security bug in cPanel/WHM found

Ceko

Registered
Aug 6, 2011
1
0
51
We have found out that 1 of our clients (a reseller) had created a common domain name "hotmail.com" and he had hijacked all emails theat were forwarded to or sent to any hotmail account from within our server.

Although there is an option in WHM---> Tweak settings ---> domains ---> blocking use of common domains.... actually this option here is only good for falsely relaxing us that as if our clients can no longer create these domains....

The truth on the other hand is that although they can not create it within their cPanels all and each reseller can easily create them from within their WHM and collect these mentioned emails of others sent/forwarded to hotmail.com addresses and we can prove it.

Please let us know if you have any fix for this security bug.

Regards
Ceko
 

JeffP.

Well-Known Member
Sep 28, 2010
164
15
68
Hi Ceko,

This issue is being tracked under case ID # 28634. Thank you for bringing this to our attention.