Skip to main content

Two-Factor Authentication Weakness Found In Website Hosting

 

The security services provider, Digital Defense recently revealed information about a 2FA vulnerability in ‘cPanel & WHM’, a website hosting platform. For your information, WHM stands for WebHost Manager, the tool that web hosting service providers offer to clients. WHM is behind more than 70 million website domain names, and it is used to offer control over virtual private servers or dedicated servers.

The said vulnerability enabled exposing 2FA to an exhaustive search attack. The provider of security solutions managed to show that it only took a couple of minutes for an effective cyberattack to happen.

The attack comes with a caveat, though. The cyberattacker would have to either know valid credentials or should have the right to use these. This would reduce their attack surface scope to insider attacks or stolen website credentials. That means over 70 million groups of credentials (granted that there is one for each domain). That also means website hosting providers would have to ensure that they have made every WHM instance up to date.

cPanel Acts To Resolve This Authentication Vulnerability

The information about the vulnerability only came to light after the release of a cPanel & WHM update. Back in November 2020, cPanel, L.L.C., released an update, and according to the company, the problem has been resolved in the following builds.

·       11.90.0.17

·         11.92.0.2

·         11.86.0.32

The senior VP of engineering for Digital Defense, Mike Cotton has responded to the issue recently. He recently said that working together with enterprises on an attempt of coordinated disclosure to enable a prompt process of resolving a vulnerability, is Digital Defense’s usual practice. Digital Defense’s Vulnerability Research Team communicated with cPanel, said Cotton while noting that cPanel worked in a diligent way on a security patch. Cotton also stated that Digital Defense would keep communicating with customers to ensure that they can act to mitigate new, potential risks due to the vulnerability.

What Does That Mean To Enterprises?

Almost every website hosted on a Linux-based server will use cPanel & WHM as its management suite. Many people regard it as the best-known and most widely deployed form of software. The fact that this kind of big flaw occurred, shows the importance of testing. Digital Defense deemed it a ‘zero-day attack’, but it gave cPanel enough time to resolve the issue in accordance with responsible disclosure policies.

Anyhow, several web hosting service providers are yet to update it to the most recent version. Every website owner has to check their cPanel version. When it is a different version, the owner has to inform the same to their web host and demand an update.

Comments

Popular posts from this blog

Things To Know About Choosing An OS For Web Hosting

  Generally, the default OS for a web server is a Unix or Linux version. There are financial and practical reasons why it is the OS for web hosting services . For one thing, Linux is a free and open-source OS, which around 70% of web servers run on. Ubuntu, Red Hat Linux and CentOS are among the commonly-used Linux distributions. It is possible to run applications accessible for a Linux distribution with other distributions, although there are certain exceptions to it. Is Linux Web Hosting More Difficult To Use? Are you concerned about your capability of working with a hosting plan based on Linux? If so, just remember that almost every web hosting service loads the server with a user-friendly Linux distribution, like Ubuntu. The settings and services that you seek might be somewhere else, but you might look forward to having high-level usage patterns and high-level privileges from a Windows or Mac server. A few Linux distributions may be closer to Apple macOS, but others are...

Reasons To Use An Unmanaged Dedicated Server

Some of the best-dedicated server providers offer unmanaged and managed hosting options. This leaves the question of when to be on an unmanaged dedicated server hosting plan. If you are unaware of what an unmanaged hosting service means, you perhaps should not have it. Here, we will discuss why and when you should be on the best dedicated hosting plan that is unmanaged. What Does Unmanaged Dedicated Server Hosting Mean? It is a dedicated server plan that offers root access, which offers the user control over custom configurations. It requires experience in server administration and expertise in the installed OS. The web host will only set up software on the server after the customer makes their selection on checkout. Otherwise, you and/or your team will be responsible for server upkeep. When to Use An Unmanaged Dedicated Server Plan You should go for an unmanaged dedicated server plan when you require not only the power that comes with this form of a server but also the flexib...

Shared Web Hosting Versus Reseller Hosting

  A web host provides the platform and technology that enables users to access websites. The service provider offers numerous packages to suit different needs, including reseller hosting and shared web hosting plans. Shared server hosting is more affordable than other web hosting options. It is good for a single website, small business site, or a site that has low traffic. Reseller hosting is for people who wish to host more than one website or sell web hosting services. Reselling is not allowed on a shared hosting plan. What Is Shared Hosting? The hosting option offers solutions that let multiple sites share the resources of one server. A shared web hosting plan is perfect for a blog and/or small site without advanced configuration requirements or high bandwidth requirements. Further, shared hosting providers divide all the server resources like Random Access Memory, mail server and CPU among customers. Unlimited domains can be hosted on a shared plan through the inclusi...