The
security services provider, Digital Defense recently
revealed information about a 2FA vulnerability in ‘cPanel & WHM’, a website
hosting platform. For your information, WHM stands for WebHost Manager, the
tool that web hosting service providers offer to clients. WHM is behind more than 70 million
website domain names, and it is used to offer control over virtual private
servers or dedicated servers.
The said
vulnerability enabled exposing 2FA to an exhaustive search attack. The provider
of security solutions managed to show that it only took a couple of minutes for
an effective cyberattack to happen.
The
attack comes with a caveat, though. The cyberattacker would have to either know
valid credentials or should have the right to use these. This would reduce their
attack surface scope to insider attacks or stolen website credentials. That means
over 70 million groups of credentials (granted that there is one for each
domain). That also means website hosting providers would have to ensure that they have made every WHM
instance up to date.
cPanel Acts
To Resolve This Authentication Vulnerability
The
information about the vulnerability only came to light after the release of a
cPanel & WHM update. Back in November 2020, cPanel, L.L.C., released an update,
and according to the company, the problem has been resolved in the following
builds.
·
11.90.0.17
·
11.92.0.2
·
11.86.0.32
The
senior VP of engineering for Digital Defense, Mike Cotton has responded to the
issue recently. He recently said that working together with enterprises on an
attempt of coordinated disclosure to enable a prompt process of resolving a
vulnerability, is Digital Defense’s usual practice. Digital Defense’s Vulnerability
Research Team communicated with cPanel, said Cotton while noting that cPanel
worked in a diligent way on a security patch. Cotton
also stated that Digital Defense would keep communicating with customers to
ensure that they can act to mitigate new, potential risks due to the
vulnerability.
What
Does That Mean To Enterprises?
Almost
every website hosted on a Linux-based server will use cPanel & WHM as its
management suite. Many people regard it as the best-known and most widely
deployed form of software. The fact that this kind of big flaw occurred, shows
the importance of testing. Digital Defense deemed it a ‘zero-day attack’, but
it gave cPanel enough time to resolve the issue in accordance with responsible
disclosure policies.
Anyhow,
several web hosting
service providers are yet to update it to the most recent version. Every
website owner has to check their cPanel version. When it is a different version,
the owner has to inform the same to their web host and demand an update.
Comments
Post a Comment