NamePros
Welcome, Guest! Ready to make a name for yourself in the domain business? We welcome both the hobbyist and professional domainer to join the discussion as part of the NamePros community.

Click here to create your profile to start earning reputation for posting, and trader ratings for buying & selling in our free e-marketplace. Build your trader rating with each successful sale. Our system has tracked over 100,000 sales and counting!
FAQ & TOS Register Search Today's Posts Mark Forums Read

Go Back   NamePros.com > Website Development Discussion Forums > Web Hosting Discussion
Reload this Page User given root access by mistake?

Web Hosting Discussion Hosting topics including DNS, control panels, servers, choosing a host, support.

Advanced Search
2 members in live chat ~  


Closed Thread
 
LinkBack Thread Tools
Old 07-26-2005, 04:48 PM THREAD STARTER               #1 (permalink)
Senior Member
 
kjmz's Avatar
Join Date: May 2005
Location: .ca
Posts: 1,277
kjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of light
 



Question User given root access by mistake?


Hi,

I recently bought a site off of eBay and I was gettin the site from cPanel when I noticed that at the top it said "Warning: You are logged in using the reseller or root password." I really didn't know what it mean't I looked a little lower and what do you know I had access to all the site on the server! (Look at screenshot attached.)

This really is not good what do you guys think I should do? Should I contact the owner of the server? This may be happening with everyone?

Comments please!
Attached Images
File Type: jpg screenshothost.JPG (75.6 KB, 41 views)
kjmz is offline  
Old 07-26-2005, 04:55 PM   #2 (permalink)
KPR
Senior Member
 
KPR's Avatar
Join Date: May 2005
Location: Sunny Scotland
Posts: 1,757
KPR has much to be proud ofKPR has much to be proud ofKPR has much to be proud ofKPR has much to be proud ofKPR has much to be proud ofKPR has much to be proud ofKPR has much to be proud ofKPR has much to be proud ofKPR has much to be proud of
 



Contact him right away incase someone who isnt as honest is able to access it all also.
KPR is offline  
Old 07-26-2005, 04:58 PM THREAD STARTER               #3 (permalink)
Senior Member
 
kjmz's Avatar
Join Date: May 2005
Location: .ca
Posts: 1,277
kjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of light
 



Originally Posted by KPR
Contact him right away incase someone who isnt as honest is able to access it all also.
Think I should ask for some money lol

I know I report someone before to Google Adsense because they had "Click the Ads Above to Support Us", they didn't even say "Thank you."

I honestly don't even know who the host is maybe if I do a nameserver check I will find out.

---------------------------------------------
????: NamePros.com http://www.namepros.com/web-hosting-discussion/110137-user-given-root-access-by-mistake.html

I just emailed him, here the email:

Hi,

I would just like to notify you that you have given me and maybe others root access. I actually bought the site speedbanner.biz from eBay and I got a cPanel account to transfer the site. I see that I could access all the sites on your server because of this. I'm just notifying you because I would hate for this to happen to me if I owned a hosting company.

I would appreciate it if I got something for pointing this out to you and not doing any damage to your server

Thanks
Last edited by kjmz; 07-26-2005 at 05:10 PM.
kjmz is offline  
Old 07-26-2005, 05:23 PM   #4 (permalink)
Senior Member
 
Scott's Avatar
Join Date: Jun 2003
Location: UK
Posts: 3,541
Scott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond repute
 

Member of the Month
February 2005

Can you login to WHM? That's non-SSL port 2086 or SSL port 2087. If so, post a screenshot of the navigation.

Thanks,
-Scott
Scott is offline  
Old 07-26-2005, 05:29 PM   #5 (permalink)
Senior Member
Join Date: Jan 2005
Location: USA
Posts: 1,149
hotrod12 has a spectacular aura abouthotrod12 has a spectacular aura about
 



All that means is that the cPanel account that he gave you is his main account or even his only account on the server. I would think that he would know what he is doing by giving you that kind of access so there should be no need to contact him but as long as you don't touch anything but the backup function then you should have no problem. Also, Scott he would definetly have access to WHM because he was given root access under the reseller/server.
hotrod12 is offline  
Old 07-27-2005, 12:39 AM   #6 (permalink)
Senior Member
 
dgaussin's Avatar
Join Date: May 2004
Location: France
Posts: 1,226
dgaussin is a splendid one to beholddgaussin is a splendid one to beholddgaussin is a splendid one to beholddgaussin is a splendid one to beholddgaussin is a splendid one to beholddgaussin is a splendid one to beholddgaussin is a splendid one to beholddgaussin is a splendid one to behold
 




You have this message when you're logged on a CPanel account using the reseller or root layer. Not the same thing to have root access... I guess you have a reseller account...
dgaussin is offline  
Old 07-27-2005, 01:00 AM   #7 (permalink)
Account Closed
 
Veolus's Avatar
Join Date: Dec 2004
Location: Australia
Posts: 4,308
Veolus has much to be proud ofVeolus has much to be proud ofVeolus has much to be proud ofVeolus has much to be proud ofVeolus has much to be proud ofVeolus has much to be proud ofVeolus has much to be proud ofVeolus has much to be proud ofVeolus has much to be proud of
 



Yep, David is most likely right in this case. It could just be a reseller account
Veolus is offline  
Old 07-27-2005, 01:46 AM   #8 (permalink)
First Time Poster!
Join Date: Aug 2004
Location: Chelmsford, UK
Posts: 11,421
Sabre has a reputation beyond reputeSabre has a reputation beyond reputeSabre has a reputation beyond reputeSabre has a reputation beyond reputeSabre has a reputation beyond reputeSabre has a reputation beyond reputeSabre has a reputation beyond reputeSabre has a reputation beyond reputeSabre has a reputation beyond reputeSabre has a reputation beyond reputeSabre has a reputation beyond repute
 

Member of the Month
March 2005
Animal Cruelty Help The Homeless - Holiday 2009
Even if its a reseller login, he can still access everyone else account on that reseller...
Sabre is offline  
Old 07-27-2005, 02:02 AM   #9 (permalink)
Senior Member
 
Scott's Avatar
Join Date: Jun 2003
Location: UK
Posts: 3,541
Scott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond reputeScott has a reputation beyond repute
 

Member of the Month
February 2005

Originally Posted by Sabre
Even if its a reseller login, he can still access everyone else account on that reseller...
Assuming there are accounts. Exactly the reason I asked for a SS, then we could verify if it's root (or not).
Scott is offline  
Old 07-27-2005, 02:32 AM THREAD STARTER               #10 (permalink)
Senior Member
 
kjmz's Avatar
Join Date: May 2005
Location: .ca
Posts: 1,277
kjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of lightkjmz is a glorious beacon of light
 



Originally Posted by Scott
Assuming there are accounts. Exactly the reason I asked for a SS, then we could verify if it's root (or not).
I tried to login and it wouldn't work. I can access all the different sites though.
kjmz is offline  
Old 07-27-2005, 02:05 PM   #11 (permalink)
NamePros Regular
Join Date: Feb 2005
Location: UK
Posts: 408
Oblivion. is a jewel in the roughOblivion. is a jewel in the roughOblivion. is a jewel in the rough
 



Originally Posted by kjmz
I tried to login and it wouldn't work. I can access all the different sites though.
Try clicking the direct link to WHM when you're logged into CPanel, After seeing the items on the top of the WHM menu, we would be able to tell if it was a reseller acount, or root access that you've got .
Oblivion. is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Adding FrontPage users and determining their access! priyanka[imported] Web Hosting Discussion 0 12-16-2004 08:14 PM
A Beginner's Guide to Securing Your Server Part 1 of 3 (Security Inside WHM/CPanel) 000000000 Webmaster Tutorials 7 10-09-2004 01:17 PM
Access denied for user redhippo Programming 6 08-26-2004 05:21 AM
Hyperpipe.net webhosting offers hyperpipe Web Hosting Offers 0 03-28-2004 03:56 AM

 
All times are GMT -7. The time now is 10:29 PM.

Domain name forum recommended by Domaining.com Powered by: vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0 Ad Management plugin by RedTyger