Results 1 to 3 of 3
  1. #1
    Join Date
    Sep 2005
    Posts
    480

    Login without using full password on WHM & Cpanel

    Just found out that our Cpanels and WHM can be logged in using only the first 8 out of 10 characters in the password field. Just received a response from tech support that this is something that they cannot fix. Apparently, it is an authentication glitch.

    Is this normal for all VPS hosts or just the one that we are with?

    I would think this is a major security glitch?

  2. #2
    Join Date
    Mar 2003
    Location
    Canada
    Posts
    8,910
    I just tried this on a couple (non VPS) servers (Current/Release) and had no luck with the method you are describing.

    My passwords are (at least) 15 characters long and it will not work unless the FULL password is entered.
    Patrick William | RACK911 Labs | Software Security Auditing
    400+ Vulnerabilities Found - Quote @ https://www.RACK911Labs.com

    www.HostingSecList.com - Security notices for the hosting community.

  3. #3
    Join Date
    Sep 2005
    Posts
    480
    Sorry for the duplicate but yet similar post but this was something that raised flags for us. Here is what one user suggested is happening. Older OS's using older authentication methods (8 characters): http://www.webhostingtalk.com/showthread.php?t=556487

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •