User password the same as root issue

littlened

Registered
Mar 27, 2006
2
0
151
Hi all,

I have Cpanel installed on a VPS. Yesterday I created a new account which used the same password as the rooter user. When I then logged into the account, I had the drop down at the top of the homepage showing all accounts on the server.

I changed the password for the user, logged out and back in again, and everything was back to normal.

I thought this was strange and wondered if this might be a bug?

I should probably also notify my hosting company.
 

Voltar

Well-Known Member
Apr 30, 2007
267
0
168
Bakersfield, California
This has been a feature of cPanel for awhile iirc, however you can disable it in WHM under Tweak Settings. I believe the setting is called "disable login to accounts using root/reseller password" or something like that.


Most of the time I leave it enabled though because at times it is nice to not have to ask for a user's password, or reset it. My root passwords are normally 64 characters though, so I don't worry about someone having the same pass as it is highly unlikely.
 
Last edited:

dansgalaxy

Well-Known Member
Jan 29, 2007
91
0
156
Reading, UK
cPanel Access Level
Root Administrator
This has been a feature of cPanel for awhile iirc, however you can disable it in WHM under Tweak Settings. I believe the setting is called "disable login to accounts using root/reseller password" or something like that.


Most of the time I leave it enabled though because at times it is nice to not have to ask for a user's password, or reset it. My root passwords are normally 64 characters though, so I don't worry about someone having the same pass as it is highly unlikely.

my point exactly ;)