lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <68cbfab10602080235w6ff80c96x3f999c600fafd598@mail.gmail.com>
Date: Wed Feb  8 10:42:41 2006
From: h4cky0u.org at gmail.com (h4cky0u)
Subject: Cpanel Admin login (username) Disclosure

Yup i could reproduce that with all the sites i tried it on.

On 2/8/06, Sumit Siddharth <sumit.siddharth@...il.com> wrote:
>
> Hi, could somebody kindly confirm this.
> When a null username and a null password is provided in the cpanel
> administration, port 2082, (basic authorization prompt) and then cancelling
> the prompt the second time, the webpage presents a hyperlink to reset the
> password which contains valid username for the cpanel administration.
> Thanks
> Sumit
>
>
> --
>
> Sumit Siddharth
>
>
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
>


--
http://www.h4cky0u.org
(In)Security at its best...
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20060208/b98a9775/attachment.html

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ