Damus
Taggart :ifin: · 12w
Ugggh this one is going to suck. cPanel is everywhere and most are not patched frequently. https://www.bleepingcomputer.com/news/security/cpanel-whm-emergency-update-fixes-critical-auth-bypass-bug
Dec [{(:no_ai:)}] profile picture
@nprofile1q...
Before the patches were released, the recommended emergency fix was to firewall off all the login ports: WHM, cPanel, and a few others (including Webmail).
Those login services are independent of the main httpd that serves up the hosted websites, and they must share a similar code base, with the same vulnerabilities.