Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

Security bug in cPanel/WHM found

Discussion in 'Security' started by Ceko, Aug 6, 2011.

  1. Ceko

    Ceko Registered

    Joined:
    Aug 6, 2011
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    51
    We have found out that 1 of our clients (a reseller) had created a common domain name "hotmail.com" and he had hijacked all emails theat were forwarded to or sent to any hotmail account from within our server.

    Although there is an option in WHM---> Tweak settings ---> domains ---> blocking use of common domains.... actually this option here is only good for falsely relaxing us that as if our clients can no longer create these domains....

    The truth on the other hand is that although they can not create it within their cPanels all and each reseller can easily create them from within their WHM and collect these mentioned emails of others sent/forwarded to hotmail.com addresses and we can prove it.

    Please let us know if you have any fix for this security bug.

    Regards
    Ceko
     
  2. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    16,443
    Likes Received:
    416
    Trophy Points:
    583
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. JeffP.

    JeffP. Well-Known Member

    Joined:
    Sep 28, 2010
    Messages:
    164
    Likes Received:
    15
    Trophy Points:
    68
    Hi Ceko,

    This issue is being tracked under case ID # 28634. Thank you for bringing this to our attention.
     
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice