Web Hosting Vodahost    

Home Take The Royal Tour! Order Now Features Prices
Go Back   Web Hosting > VodaHost Web Hosting Support > CPanel - Control Panel

Notices

CPanel - Control Panel All Cpanel questions and issues.

Closed Thread
 
Thread Tools
  #1  
Old 05-16-2006, 10:36 PM
Sergeant Major
 
Join Date: Sep 2005
Location: Missouri
Posts: 89
Default Can someone gain access to my cp through attachments?

I recently was using horde email to send someone a file attachment. I cc'd myself and in my email was the link, when I clicked on that, the download box popped up but on that box, it included the ip address EXAMPLE:

from 80.26.852.62:5060 and when I punched that into my address bar, I got right into my control panel? Does this mean others could do the same if I use Horde to send attachments to people? And if so, what can I do to prevent that. I saw when I was composing the email, it gave me an option for "inline" is that different? Thanks in advance for your help.

WG
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #2  
Old 05-16-2006, 10:44 PM
Andy128's Avatar
Major General
 
Join Date: Dec 2005
Location: Michigan
Posts: 2,308
Default Re: Can someone gain access to my cp through attachments?

I suggest you open a support ticket as this is not normal. I tried as you did with my squirrel mail and did not have the same results.

Definetly a security issue.

Andy
__________________
My diamond in the rough - www.123gpp.com

* Click here for some BV tutorials (Php mailto Form, I-Frames, Picture display and much, much more!)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #3  
Old 05-16-2006, 11:09 PM
Sergeant Major
 
Join Date: Sep 2005
Location: Missouri
Posts: 89
Default Re: Can someone gain access to my cp through attachments?

Andy, thanks and I will open a support ticket. It seems however that once I logged out of my cpanel that once you put that ip address in again, it asks for your user name and password but still that tells me that if I send attachments and am still logged into my cp that if someone wanted to play around they could do just as I did and get into my cp.....thanks again!

Wg
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #4  
Old 05-16-2006, 11:11 PM
navaldesign's Avatar
General & Forum Moderator
 
Join Date: Oct 2005
Location: Italy
Posts: 10,052
Default Re: Can someone gain access to my cp through attachments?

But it doesn't take you to your control panel. It takes you to the login popup, where username and password are required. It's excactly the same as if you had typed www.yourdomain.com/webmail . Noone can login in your CP without username and password
__________________
Navaldesign
Logger Lite: Low Cost, Customizable, multifeatured Login script
Instant Download Cart: a Powerfull, Customized, in site, DB driven, e-products Cart
DBTechnosystems.com Forms, Databases, Shopping Carts, Instant Download Carts, Loggin Systems and more....
Advanced BlueVoda Form Processor : No coding form processor! Just install and use! Now with built in CAPTCHA!


Last edited by navaldesign; 05-17-2006 at 07:06 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #5  
Old 05-17-2006, 06:39 AM
racefan20's Avatar
Major General
 
Join Date: Jul 2005
Location: Concord, NC
Posts: 2,350
Default Re: Can someone gain access to my cp through attachments?

Quote:
Originally Posted by wgreene
Andy, thanks and I will open a support ticket. It seems however that once I logged out of my cpanel that once you put that ip address in again, it asks for your user name and password but still that tells me that if I send attachments and am still logged into my cp that if someone wanted to play around they could do just as I did and get into my cp.....thanks again!

Wg
Navaldesign's answer above mine pretty much answers this, but I wanted to add one thing in response to this: "if I send attachments and am still logged into my cp that if someone wanted to play around they could do just as I did and get into my cp"

This is not possible, so don't worry. A log in is unique to the pc you are on and anyone else would see the username and password screen whether you're logged into your cpanel or not.
__________________
My NASCAR Forum
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #6  
Old 05-17-2006, 11:36 AM
VodaHost's Avatar
General & Forum Administrator
 
Join Date: Mar 2005
Location: Wilmington, Delaware USA
Posts: 8,658
Default Re: Can someone gain access to my cp through attachments?

80.26.852.62:5060 is not your control panel, it does not even belong to VodaHost.
__________________
VodaHost
Your Website People!
1-302-283-3777 North America / International
07092887580 / United Kingdom

Military Ranking System Explained


Click Here to take the royal VodaHost Tour
Click Here for the VodaHost Help Centre & Tutorials
Got a question? - Try a forum search! Available at the top of every page!

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #7  
Old 05-17-2006, 10:52 PM
Sergeant Major
 
Join Date: Sep 2005
Location: Missouri
Posts: 89
Default A picture of exactly what happened.

A picture of exactly what happened! I guess I was a little upset that vodahost acted as if I were lying when I was only trying to help. This is what I "think" happened. The file I sent was an mp3. I attached the mp3 from my computer as track 9.mp3. It just so happens that I have multiple track 9.mp3's uploaded on the server so maybe after I attached the file it somehow associated it with the file on the server....I really don't know that is just a wild guess but as you can see the link clearly indicates that it was sent from Horde. All in all I am here to help others just as many have helped me...that's all!

Dear Laura Dunkin,

The ip address I gave you was an EXAMPLE as my original email indicated. Your support page is not secure which even asks for your customers user name and password so thats why I was using an example. The IP address was 70.86.134.194:2082 and YES it did take me directly to my control panel and I am insulted that you would insinuate that I was not telling the truth. I am a paying customer and was only trying to help by explaining EXACTLY what happened. I love your service and am happy with Vodahost but please give your customers the benefit of the doubt when discussing security issues or other important matters in the future.

Regards
Wilson

Their Reply
80.96.654.365:6050 is not a CP of any sort. That IP does not even belong to us.

I suggest you try it again as I highly doubt it took you to your cpanel control panel. That ip does not belong to us, nor is that the cpanel port.

Original From ME
Today, I was using Horde email and sent an attachment to a friend. I cc'd myself and when I checked my inbox and clicked on the link, the normal download window popped up (after a message stating my site could possible contain a virus)....also on the download box was the following statement

from: 80.96.654.365:6050 (example ip) When I placed that ip address into my window it took me directly into my cp which is a huge security breach. Now once I logged out of my cp and I put the same ip address in, the username passowrd box came up. I just thought you should know about this. I won't be using Horde anytime soon. I only used that because I could change my identity to have my emails say from hiphoptraxx.com and not some ext. at yahoo.

Thanks
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #8  
Old 05-17-2006, 11:17 PM
navaldesign's Avatar
General & Forum Moderator
 
Join Date: Oct 2005
Location: Italy
Posts: 10,052
Default Re: Can someone gain access to my cp through attachments?

Don't think anyone said you are lying. Vodahost Admin is not in continous contact and aware of all (more than 1000/day) support tickets., so could not know that this was an example. It is also obvious that whoever responded to your ticket, didn't notice the (example ip) otherwise he would't have answered that way. Errare umanun est.
__________________
Navaldesign
Logger Lite: Low Cost, Customizable, multifeatured Login script
Instant Download Cart: a Powerfull, Customized, in site, DB driven, e-products Cart
DBTechnosystems.com Forms, Databases, Shopping Carts, Instant Download Carts, Loggin Systems and more....
Advanced BlueVoda Form Processor : No coding form processor! Just install and use! Now with built in CAPTCHA!

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #9  
Old 05-17-2006, 11:30 PM
Sergeant Major
 
Join Date: Sep 2005
Location: Missouri
Posts: 89
Default Re: Can someone gain access to my cp through attachments?

Yes, I agree and mistakes can be made but thats why it's important to actually read the email. Anyway, I will wait to see if they have any ideas as to what happened. Thanks for the reply and aren't you missing an "h" in your latin reply there? Errare Humanun est. ?


Don't think anyone said you are lying. Vodahost Admin is not in continous contact and aware of all (more than 1000/day) support tickets., so could not know that this was an example. It is also obvious that whoever responded to your ticket, didn't notice the (example ip) otherwise he would't have answered that way. Errare umanun est.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #10  
Old 05-17-2006, 11:48 PM
navaldesign's Avatar
General & Forum Moderator
 
Join Date: Oct 2005
Location: Italy
Posts: 10,052
Default Re: Can someone gain access to my cp through attachments?

You see ? Errare Humanun est.

And, the explanation is simple: you had the link to download the attachment. If you were logged in your CP, or you were just minutes ago, your computer simply logged in directly without need for pas and username. Try it this way: connect to your CP. Then type in the address bar another address, f.e. the forum one www.vodahost.com/vodatalk then type in again the address of your CP. You will see that the second time, you are not asked for username and password, unless you had unloged before
__________________
Navaldesign
Logger Lite: Low Cost, Customizable, multifeatured Login script
Instant Download Cart: a Powerfull, Customized, in site, DB driven, e-products Cart
DBTechnosystems.com Forms, Databases, Shopping Carts, Instant Download Carts, Loggin Systems and more....
Advanced BlueVoda Form Processor : No coding form processor! Just install and use! Now with built in CAPTCHA!

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #11  
Old 05-18-2006, 12:08 AM
Sergeant Major
 
Join Date: Sep 2005
Location: Missouri
Posts: 89
Default Re: Can someone gain access to my cp through attachments?

Well stated navaldesign and yes you are correct. I just wish the downloaded link would mask the "real' link. Am I right in saying that if I was still logged into my cp and someone put in the direct url to my cp in their address bar that they would be able to get into my cp as well? If so, Someone who wanted to be mean could cause a little bit of mischief if they wanted to. Thanks for the reply!

You see ? Errare Humanun est.

And, the explanation is simple: you had the link to download the attachment. If you were logged in your CP, or you were just minutes ago, your computer simply logged in directly without need for pas and username. Try it this way: connect to your CP. Then type in the address bar another address, f.e. the forum one www.vodahost.com/vodatalk then type in again the address of your CP. You will see that the second time, you are not asked for username and password, unless you had unloged before
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #12  
Old 05-18-2006, 12:42 AM
racefan20's Avatar
Major General
 
Join Date: Jul 2005
Location: Concord, NC
Posts: 2,350
Default Re: Can someone gain access to my cp through attachments?

Quote:
Originally Posted by wgreene
Well stated navaldesign and yes you are correct. I just wish the downloaded link would mask the "real' link. Am I right in saying that if I was still logged into my cp and someone put in the direct url to my cp in their address bar that they would be able to get into my cp as well? If so, Someone who wanted to be mean could cause a little bit of mischief if they wanted to. Thanks for the reply!
This is not possible, so don't worry. A log in is unique to the pc you are on and anyone else would see the username and password screen whether you're logged into your cpanel or not.
__________________
My NASCAR Forum
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
  #13  
Old 05-18-2006, 01:47 AM
Sergeant Major
 
Join Date: Sep 2005
Location: Missouri
Posts: 89
Default Re: Can someone gain access to my cp through attachments?

Wilson is very relieved! Thanks racefan20 and navaldesign for all the explanations.....With all of this knowledge soaking in, I'll be a General in no time!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off



All times are GMT +1. The time now is 04:30 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC7
2005-2009 VodaHost Web Hosting Your Perfect Web Host - All Rights Reserved

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203