Cpanel recently announced a new vulnerability for their servers for the password reset option. We'll show you how to turn off the password reset option for failed logins to Cpanel through Web Host Manager.
Description The feature "Allow cPanel users to reset their password via email", found in WebHostManager in the "Tweak Settings" section allows for a cpanel user to run some commands as the root user.
It's strongly suggested that all Cpanel users disable this feature.
Affected Systems All builds of Cpanel on all platforms are vulnerable up to and including (9.1.0 build 34), all builds after that have been fixed.
Step 1) Fixing The Problem - Disable It
1. Login into you WHM control panel as root.
2. Click on Tweak Settings in the upper left hand corner.
3. Scroll down until you see "Allow cPanel users to reset their password via email"
4. Uncheck the check box and click Save.
Click the screenshot for a larger image.
Article provided by WebHostGear.com
Step 2) Fixing The Problem - Update Cpanel You can also update your Cpanel server to the latest release, which now fixes this issue.
Article provided by WebHostGear.com
1. Login into you WHM control panel as root.
2. Click on Upgrade to Latest Version on the bottom right hand corner.
Get professional help with your configuration, script installation or server issue. Learn how we can help you with any server problem and make your server run like new. Professional staff will contact you, after submitting a quote request, by phone or email.
WebHostGear Hire an Expert - NEW! Let us improve your servers performance, find that spammer and take care of that kernel upgrade. Hire us to help with any tutorials listed on the site or any other services needed. Get your free, NO obligation quote now
Our site offers free hosting tutorials, cpanel tutorial, web hosting news, shell commands, running a web hosting business, dedicated guides, linux tutorial, apache install, home web server, web server guide, ssh commands, dedicated servers, DNS nameservers, chkrootkit, apf firewall, exim configuration, server compromised, cron backup solution, ftp backup script