• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
2 Factor Authentication Bypass Flaw Reported In Cpanel And Whm Software

2-Factor Authentication Bypass Flaw Reported in cPanel and WHM Software

You are here: Home / General Cyber Security News / 2-Factor Authentication Bypass Flaw Reported in cPanel and WHM Software

cPanel, a service provider of common administrative applications to handle web hosting, has patched a security vulnerability that could have allowed remote attackers with access to legitimate credentials to bypass two-factor authentication (2FA) defense on an account.

The issue, tracked as “SEC-575” and uncovered by researchers from Digital Defense, has been remedied by the company in versions 11.92..2, 11.90..17, and 11.86..32 of the program.

cPanel and WHM (Web Host Manager) provides a Linux-based mostly control panel for consumers to cope with internet site and server management, which include duties this kind of as introducing sub-domains and accomplishing method and command panel servicing. To date, around 70 million domains have been introduced on servers applying cPanel’s software package suite.

✔ Approved Seller by TheCyberSecurity.News From Our Partners
Avast Ultimate Suite 2021

Protect yourself against all threads using AVAST Ultimate Suite. AVAST Ultimate Suite protects your Windows, macOS and your Android via Avast Premium. In addition it comes with AVAST's well-known VPN service SecureLineVPN. Therefore, it will be a security and privacy in one package.

Get AVAST Ultimate Suite with 65% discount certified seller: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The issue stemmed from a deficiency of level-limiting during 2FA during logins, hence building it achievable for a malicious party to regularly submit 2FA codes applying a brute-pressure method and circumvent the authentication verify.

Digital Protection researchers reported an attack of this type could be accomplished in minutes.

“The two-factor authentication cPanel Security Coverage did not reduce an attacker from consistently submitting two-factor authentication codes,” cPanel mentioned in its advisory. “This authorized an attacker to bypass the two-factor authentication examine applying brute-power procedures.”

The company has now resolved the flaw by incorporating a price restrict test to its cPHulk brute-pressure security support, producing a unsuccessful validation of the 2FA code to be treated as a unsuccessful login.

This is not the very first time the absence of charge-limiting has posed a serious security problem.

Back again in July, movie conferencing application Zoom mounted a security loophole that could have allowed potential attackers to crack the numeric passcode applied to protected non-public meetings on the system and snoop on members.

It truly is suggested that cPanel shoppers use the patches to mitigate the risk affiliated with the flaw.

Discovered this short article intriguing? Abide by THN on Facebook, Twitter  and LinkedIn to study much more exceptional material we article.


Some components of this posting are sourced from:
thehackernews.com

Previous Post: «Baidu's Android Apps Caught Collecting And Leaking Sensitive User Data Baidu’s Android Apps Caught Collecting and Leaking Sensitive User Data
Next Post: E-Commerce Biz and CEO Charged with Investor Fraud Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • Big Tech Bans Social Networking App
  • Lack of Funding Could Lead to “Lost Generation” of Cyber-Startups
  • Unveiled: SUNSPOT Malware Was Used to Inject SolarWinds Backdoor
  • ‘I’ll Teams you’: Employees assume security of links, file sharing via Microsoft comms platform
  • DarkSide decryptor unlocks systems without ransom payment – for now
  • Researchers see links between SolarWinds Sunburst malware and Russian Turla APT group
  • Millions of Social Profiles Leaked by Chinese Data-Scrapers
  • Feds will weigh whether cyber best practices were followed when assessing HIPAA fines
  • SolarWinds Hack Potentially Linked to Turla APT
  • 10 quick tips to identifying phishing emails

Copyright © TheCyberSecurity.News, All Rights Reserved.