+ Reply to Thread
Page 2 of 2 FirstFirst 12
Results 21 to 37 of 37

Thread: Does Webhosting Buzz Allow Unauthorized FTP Access?

  1. #21
    Colin's Avatar
    Colin is offline Wait, What?
    Join Date
    Aug 2007
    Posts
    175
    WHB Points this Month
    0.00
    WHB Points
    5.00
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    If so, then good, however, I had that feature disabled on a previous version of cPanel, seems one of the recent upgrades may have enabled it. And having it enabled, if the WHB global, err, barfs, and switches to enabled, means that every website which it is still enabled becomes vulnerable.

  2. #22
    Maxim M.'s Avatar
    Maxim M. is offline WeeHBie
    Join Date
    Sep 2008
    Location
    Kharkiv, UA
    Posts
    545
    Servers
    webhostingbuzz.com
    WHB Points this Month
    5.00
    WHB Points
    55.00
    Thanks
    14
    Thanked 3 Times in 3 Posts

    Default

    Anonymous FTP access is disabled on all our shared servers by default. Moreover, it cannot be enabled in cPanel.

  3. #23
    Alan B's Avatar
    Alan B is offline Super Moderator
    Join Date
    Jul 2007
    Location
    Toronto, Canada
    Posts
    1,386
    WHB Points this Month
    0.00
    WHB Points
    290.00
    Thanks
    0
    Thanked 5 Times in 5 Posts

    Default

    Good, that's what I thought. Thanks for that confirmation, Maxim.

    It seems that the original poster's problem with unathorized access to his account was caused by someone obtaining his passwords, not by a flaw in cPanel.
    I am not WHB staff and I am not paid.
    I provide help in these forums on my own time.

  4. #24
    Keith is offline Got Hacked!
    Join Date
    Jul 2006
    Posts
    27
    WHB Points this Month
    0.00
    WHB Points
    0.00
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    Quote Originally Posted by Colin View Post
    Make sure this:
    Allow anonymous access to ftp://ftp.yourdomain.com
    Is not enabled under cPanel's Anonymous FTP Controls
    Just now read this. It WAS enabled in my cpanel. I unchecked it. That must be a default setting.

  5. #25
    Keith is offline Got Hacked!
    Join Date
    Jul 2006
    Posts
    27
    WHB Points this Month
    0.00
    WHB Points
    0.00
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    Alsio I found this thread that is definitely of interest to everyone....

    http://www.webdeveloper.com/forum/sh....php?p=1001327

  6. #26
    Keith is offline Got Hacked!
    Join Date
    Jul 2006
    Posts
    27
    WHB Points this Month
    0.00
    WHB Points
    0.00
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    I checked several other accounts I host for allowing anonymous access. Several were enabled but not all of them. I changed them to unallowed.

  7. #27
    Alan B's Avatar
    Alan B is offline Super Moderator
    Join Date
    Jul 2007
    Location
    Toronto, Canada
    Posts
    1,386
    WHB Points this Month
    0.00
    WHB Points
    290.00
    Thanks
    0
    Thanked 5 Times in 5 Posts

    Default

    It's good to uncheck that option, however: anonymous FTP is disabled on all servers by WHB. That default is done at a "higher level" than your individual cPanel setting.

    Your problem was not caused by anonymous FTP. Somehow your passwords were used. The fact that the unauthorized access stopped as soon as you changed your passwords seems to confirm that.
    I am not WHB staff and I am not paid.
    I provide help in these forums on my own time.

  8. #28
    Keith is offline Got Hacked!
    Join Date
    Jul 2006
    Posts
    27
    WHB Points this Month
    0.00
    WHB Points
    0.00
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    Quote Originally Posted by Alan B View Post
    It's good to uncheck that option, however: anonymous FTP is disabled on all servers by WHB. That default is done at a "higher level" than your individual cPanel setting.

    Your problem was not caused by anonymous FTP. Somehow your passwords were used. The fact that the unauthorized access stopped as soon as you changed your passwords seems to confirm that.
    That is good to know and I hope you are right because that is under the users control. Is there a way to change the ftp account username as well if necessary?

    Also do you have a suggestion for a good password generating program? I know there is one within webhost as well but I'm not sure that it is even secure enough.

    It's interesting that Yahoo is carrying an article on web security today that speaks to hacked passwords. http://tech.yahoo.com/blogs/null/141067

  9. #29
    Alan B's Avatar
    Alan B is offline Super Moderator
    Join Date
    Jul 2007
    Location
    Toronto, Canada
    Posts
    1,386
    WHB Points this Month
    0.00
    WHB Points
    290.00
    Thanks
    0
    Thanked 5 Times in 5 Posts

    Default

    You should use a long password containing a mix of upper- and lower-case letters, numbers and special characters such as #, *, ~, ?, -, etc. There likely are password-generating tools available on-line if you search.
    Last edited by Alan B; 04-29-2009 at 08:36 PM.
    I am not WHB staff and I am not paid.
    I provide help in these forums on my own time.

  10. #30
    Anna M.'s Avatar
    Anna M. is offline WeeHBie
    Join Date
    Dec 2008
    Posts
    453
    WHB Points this Month
    0.00
    WHB Points
    50.00
    Thanks
    2
    Thanked 6 Times in 3 Posts

    Default

    2Keith

    There is no way to change usernames for additional ftp accounts
    You can only delete one and create another
    As for main ftp, which username matches cpanel login, we can change it for you.
    To do that you need to submit a ticket to our tech dept at whbsupport.com
    But in fact complicated password which can't be fetched through your computer is enough to provide your account security

  11. #31
    Tony's Avatar
    Tony is offline Bad Influence
    Join Date
    Apr 2007
    Location
    West Virginia Blue Ridge
    Posts
    604
    Servers
    SS3
    WHB Points this Month
    15.00
    WHB Points
    175.00
    Thanks
    2
    Thanked 8 Times in 8 Posts

    Default

    I wonder what the current maximum length of an FTP password is on these servers? Yes, these are easily generated and stored (and never typed!) by an app like Roboform.

  12. #32
    Alan B's Avatar
    Alan B is offline Super Moderator
    Join Date
    Jul 2007
    Location
    Toronto, Canada
    Posts
    1,386
    WHB Points this Month
    0.00
    WHB Points
    290.00
    Thanks
    0
    Thanked 5 Times in 5 Posts

    Default

    Most FTP clients will store the passwords if desired, without need of a separate app like Roboform.
    I am not WHB staff and I am not paid.
    I provide help in these forums on my own time.

  13. #33
    Anna M.'s Avatar
    Anna M. is offline WeeHBie
    Join Date
    Dec 2008
    Posts
    453
    WHB Points this Month
    0.00
    WHB Points
    50.00
    Thanks
    2
    Thanked 6 Times in 3 Posts

    Default

    generally, a password utilizing at least 8 characters including alphanumeric and grammatical symbols is sufficient.
    but you may try more if you find it necessary

  14. #34
    Keith is offline Got Hacked!
    Join Date
    Jul 2006
    Posts
    27
    WHB Points this Month
    0.00
    WHB Points
    0.00
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    I reset all of mine using the Web Host Manager's password generating tool. I set it to 15 characters. I think that will do it! Thanks again for all of your help and sorry to be such a pain.

  15. #35
    Anna M.'s Avatar
    Anna M. is offline WeeHBie
    Join Date
    Dec 2008
    Posts
    453
    WHB Points this Month
    0.00
    WHB Points
    50.00
    Thanks
    2
    Thanked 6 Times in 3 Posts

    Default

    no problem =)

  16. #36
    Tony's Avatar
    Tony is offline Bad Influence
    Join Date
    Apr 2007
    Location
    West Virginia Blue Ridge
    Posts
    604
    Servers
    SS3
    WHB Points this Month
    15.00
    WHB Points
    175.00
    Thanks
    2
    Thanked 8 Times in 8 Posts

    Default

    Quote Originally Posted by Alan B View Post
    Most FTP clients will store the passwords if desired, without need of a separate app like Roboform.
    This might be safe on your personal computer - I do it myself at home. However, when logging in from elsewhere, I allow no passwords to be stored locally, and instead use Portable Roboform on my flash drive.

    8 characters is a fairly weak password these days. even my home network uses what - 64? But 256 is more reasonable.

    Maybe the lesson we'd be good to take away from this thread is that we should now STOP storing these ftp passwords locally.

  17. #37
    Maxim M.'s Avatar
    Maxim M. is offline WeeHBie
    Join Date
    Sep 2008
    Location
    Kharkiv, UA
    Posts
    545
    Servers
    webhostingbuzz.com
    WHB Points this Month
    5.00
    WHB Points
    55.00
    Thanks
    14
    Thanked 3 Times in 3 Posts

    Default

    There exist plenty of viruses (such as trojans for example) that could find passwords stored locally and send them via the Net.
    I hope everyone has antiviral software installed and keeps its database updated.
    Nevertheless we can't feel absolutely secure.
    Hope I don't seem paranoiac

+ Reply to Thread
Page 2 of 2 FirstFirst 12

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts