Web Hosting Talk







View Full Version : Those using WHM Autopilot


Hosted.cc
01-08-2005, 03:43 PM
Gulftech.org finds security holes in online scripts. Here is a recent report:

Started by a webhost looking for more out of a simple managment script, Brandee Diggs (Owner of Spinn A Web Cafe, Founder of Benchmark Designs) setout to build an internal management system that could handle the day to day operations of a normal hosting company. The key was to remove the need to constantly watch your orders and manage the installs. Alas, WHM AutoPilot was born. [ as quoted from their official website ] WHM Autopilot is vulnerable to a number of vulnerabilities such as cross site scripting, file inclusion, and information disclosure.

For more information, visit: http://www.gulftech.org/?node=research

I don't know what should be done about this as I am not a user of autopilot, contact Gulftech for further details.

NE-Adam
01-08-2005, 03:54 PM
Technically such problems such be tackled by WHM AutoPilot and updates made avaliable to plug such holes. :D

Hosted.cc
01-08-2005, 04:06 PM
Great, wasn't sure as I am not a user.

Bloory
01-08-2005, 04:11 PM
WHMAutopilot worked hard and issued a new release designed to address this (I believe).

Of course, users do need to undertake the upgrade.

RackWorx
01-08-2005, 07:49 PM
They released a 2.5 version of the script to cover up most of the new vulnerabilities found.

Rax
01-08-2005, 09:57 PM
That was patched a week ago.

boeki
01-09-2005, 10:30 AM
the patch was released 12/29 on the licensee pages and announced 12/31.