• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
  • / yourpost
home / News / cPanel - WHM update immediately

cPanel - WHM update immediately

26/11/2020 18:18 by giorgos

A security loophole in the cPanel web hosting application allows intruders to bypass two-factor authentication (2FA) with brute-force attacks on domains that use vulnerable versions of cPanel - WebHost Manager (WHM).

CPanel is a management software that is installed on web hosting servers and allows administrators and site owners to automate server and page management, providing a graphical interface.cpanel whm - cPanel - WHM update immediately

The vulnerability has been recorded as CVE-2020-27641, and was discovered by researchers Michael Clark and Wes Wright of Digital Defense.

Intruders could use CVE-2020-27641 to bypass 2FA on cPanel accounts on millions of sites because cPanel Security Policy does not prevent them from repeatedly submitting two-factor authentication codes.

"Once the MFA is enabled, a user can make as many attempts as they want to find the MFA key without delay and without a ban to prevent a brute-force attack," the researchers said.

"This leads to a scenario where an intruder with valid credentials could bypass MFA protections on an account in a matter of hours. "Our tests have shown that with the best coordination of the attack, it can be achieved in a matter of minutes."

The cPanel has already issued security updates for vulnerabilities in cPanel & WHM versions 11.92.0.2, 11.90.0.17 and 11.86.0.32. All new releases are available through the Software Update.

Of course, anyone using cPanel is advised to update immediately, or contact the company directly for more details if needed.

cPanel - WHM update immediately was last modified: 26 November, 2020, 6: 18 pm by giorgos

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: Newstag: cpanel, WHM

You May Also Like

cpanel
Violation to cPanel, data was stolen
cpanel
CPanel support is hacked
Joker's Stash closes the largest market for stolen cards

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « mimikatz Playing with Windows Security! Windows 10X RTM in December, final release in spring
Next Post: Black Friday Windows 10 Pro at 3.14 € Office Lifetime 13.99 € »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loading Cancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.