FORUM HOME | WHUK BLOG   
WEB HOSTING UK AFFORDABLE WEBSITE HOSTING SERVICES IN UNITED KINGDOM
PHP LINUX SHARED HOSTING WINDOWS ASP.NET HOSTING PACKAGES
ECOMMERCE HOSTING ASP MSSQL MS ACCESS ODBC FRONTPAGE HOSTING
CPANEL WHM FANTASTICO RESELLER DEDICATED SERVER WEB HOSTING
CHEAP PLESK CPANEL HTML MYSQL BEST UK VPS HOSTING COMPANY
CHEAP RELIABLE UK HOSTING PROVIDER SINCE 2001
MANAGED WEB HOSTING SERVICE
AFFORDABLE WEBSITE HOSTING SERVICES IN UNITED KINGDOM

Web Hosting UK Forums | Linux Windows Dedicated Server and cPanel VPS Hosting Forum » WebHosting UK News » Network Status

Reply
 
LinkBack Thread Tools Display Modes

  #1 (permalink)  
Old 28-04-09, 01:30 PM
Sales Manager
 
Join Date: May 2006
Posts: 1,560
Send a message via AIM to James Send a message via MSN to James Send a message via Yahoo to James
Default FTP access disabled for main cPanel admin accounts

We are currently in the process of disabling the default FTP login access (cpanel master user ) on all our cPanel Shared Hosting Servers. If you have a Linux cPanel Shared Hosting Account with us, you will need to login in your cpanel control panel and create a new FTP account from "FTP Manager section". In order to access your account via FTP, you will need to use this new FTP user login from now onwards. The master cPanel login username will no longer work for FTP access.

We had to take this step as many of our customers had their websites defaced with iFrame Injections on their websites. Customers who save their FTP login credentials in FTP softwares like WS_FTP_Pro, FileZilla, Cute-FTP, Dreamweaver or Frontpage are prone to such FTP iFrame Injections. Your login credentials are broadcasted to the hackers once a Windows Virus gets installed on your computer. You are exposed to same threat even if you have a Dedicated Server or Virtual Private Server or a Semi-Dedicated Server with us or any other hosting company. Resellers should notify their customers about this problem and ask them to avoid saving login credentials in Browser or FTP Softwares. The easiest way to save your login credentials would be to save them in a text document without saving the Domain name or Login Host information in the same text document. To be absolutely sure your FTP account won’t get compromised, we highly recommend you choose a strong password which contains a combination of upper and lower case letters, numbers and special characters such as #^&*$?£;: while adding a new FTP login name from your cpanel control panel. Webmasters, who manage multiple websites may not like this change, but losing your data and then losing your rankings in Search Engines will create more trouble.

There is no need to change your cpanel login password as FTP access has been disabled for the master cpanel login username only. Please donot attempt to use your existing cpanel master username for FTP as multiple failed login attempts will block your local IP on the server resulting in no access to your website from your computer.
__________________
WebHosting.UK.com :: Leader in Web Hosting
cPanel Hosting | Windows Hosting | Reseller Hosting | CLOUD HOSTING 100% Uptime
Dedicated Servers - Fully Managed UK dedicated servers with 24x7x365 Support
Great Opportunity:: Join our Affiliate Program for FREE & earn up to £300 per sale.
Follow Us on Twitter and FaceBook
Reply With Quote

  #2 (permalink)  
Old 28-04-09, 02:23 PM
MrTWS's Avatar
Senior Member
 
Join Date: May 2008
Posts: 203
Default

Hi James - would this produce an error when logging into Plesk like below?
Secure Connection Failed

92.48.98.14:8443 uses an invalid security certificate.
The certificate expired on 22/04/2009 11:19 AM.
(Error code: sec_error_expired_certificate)

I'm using Firefox 3.09
__________________
Web Design Services
Reply With Quote

  #3 (permalink)  
Old 28-04-09, 09:52 PM
Sales Team
 
Join Date: Sep 2006
Posts: 1,628
Send a message via MSN to Harry Send a message via Skype™ to Harry
Default

Quote:
Originally Posted by MrTWS View Post
Hi James - would this produce an error when logging into Plesk like below?
Secure Connection Failed

92.48.98.14:8443 uses an invalid security certificate.
The certificate expired on 22/04/2009 11:19 AM.
(Error code: sec_error_expired_certificate)

I'm using Firefox 3.09
Above error message has nothing to do with update we have made on our cpanel shared server as your account is hosted on Windows server
__________________
UK VPS Hosting || Managed Server Hosting || Reseller Hosting
Looking for extra revenue ?
Join our webhosting affiliate program and earn upto £300 Webhosting UK Affiliate
Reply With Quote

  #4 (permalink)  
Old 29-04-09, 05:21 AM
MrTWS's Avatar
Senior Member
 
Join Date: May 2008
Posts: 203
Default

I appreciate that - can Web Hosting UK examine to see if their certificate is current or was this a glitch? as it still says the same today
__________________
Web Design Services
Reply With Quote

  #5 (permalink)  
Old 29-04-09, 10:32 AM
sysadmin's Avatar
Administrator
 
Join Date: Oct 2006
Posts: 295
Post

Quote:
Originally Posted by MrTWS View Post
I appreciate that - can Web Hosting UK examine to see if their certificate is current or was this a glitch? as it still says the same today
Certificate renewed, please give a try on accessing the control panel now you might want to add an exception when browsing the new certificate for the first time..
Reply With Quote

  #6 (permalink)  
Old 29-04-09, 04:28 PM
Dan's Avatar
Dan Dan is offline
Got root?
 
Join Date: Aug 2007
Location: England, UK.
Posts: 1,340
Send a message via ICQ to Dan Send a message via AIM to Dan Send a message via MSN to Dan Send a message via Yahoo to Dan Send a message via Skype™ to Dan
Default

Quote:
Originally Posted by James View Post
We have turned off default FTP access for main cPanel admin accounts on all our shared web hosting servers because a sustained FTP brute force attack was targeting our shared servers. During security audit our Admins have noticed that number of malicious scripts were uploaded via FTP on the server using legit cPanel login details and the account owners were not even aware of such incidence.

Usually customers using weak FTP passwords are more susceptible to such attacks. We can change the FTP port but its not going to solve the problem. We strictly recommend all our clients to use strong FTP passwords. A strong password comprises of upper case, lower case, numeric and special characters. You should use the combination of these characters to build strong passwords for your FTP accounts.

There is no need to change your cpanel login password as FTP access has been disabled for the master cPanel login username.
Thanks for the info James
__________________
Webhosting.UK.com || cPanel VPS Hosting || Reseller Hosting

Sales: 0808-262-0855
Support: 0800-612-8725
International: +44 191 303 8191
Reply With Quote

  #7 (permalink)  
Old 29-04-09, 04:42 PM
Sales Manager
 
Join Date: May 2006
Posts: 1,560
Send a message via AIM to James Send a message via MSN to James Send a message via Yahoo to James
Default

You're welcome Dan.
__________________
WebHosting.UK.com :: Leader in Web Hosting
cPanel Hosting | Windows Hosting | Reseller Hosting | CLOUD HOSTING 100% Uptime
Dedicated Servers - Fully Managed UK dedicated servers with 24x7x365 Support
Great Opportunity:: Join our Affiliate Program for FREE & earn up to £300 per sale.
Follow Us on Twitter and FaceBook
Reply With Quote

  #8 (permalink)  
Old 29-04-09, 05:38 PM
MrTWS's Avatar
Senior Member
 
Join Date: May 2008
Posts: 203
Default

Quote:
Originally Posted by sysadmin View Post
Certificate renewed, please give a try on accessing the control panel now you might want to add an exception when browsing the new certificate for the first time..
PM sent to you
__________________
Web Design Services
Reply With Quote

  #9 (permalink)  
Old 30-04-09, 04:22 AM
sysadmin's Avatar
Administrator
 
Join Date: Oct 2006
Posts: 295
Smile

Quote:
Originally Posted by MrTWS View Post
PM sent to you
Replied
Reply With Quote

  #10 (permalink)  
Old 30-04-09, 11:54 AM
new member
 
Join Date: Apr 2009
Posts: 2
Default

Hi

Is there any time frame when FTP might be enabled?

Regards

Simon

Quote:
Originally Posted by James View Post
We have turned off default FTP access for main cPanel admin accounts on all our shared servers because a sustained FTP brute force attack was targeting our shared servers. During security audit our Admins have noticed that number of malicious scripts were uploaded via FTP on the server using legit cPanel login details and the account owners were not even aware of such incidence.
Reply With Quote

  #11 (permalink)  
Old 30-04-09, 12:54 PM
Sales Manager
 
Join Date: May 2006
Posts: 1,560
Send a message via AIM to James Send a message via MSN to James Send a message via Yahoo to James
Default

Hello Simon,

FTP access has been permanently disabled for main cPanel admin accounts. We are not going to enable it on any of our shared/reseller servers.
__________________
WebHosting.UK.com :: Leader in Web Hosting
cPanel Hosting | Windows Hosting | Reseller Hosting | CLOUD HOSTING 100% Uptime
Dedicated Servers - Fully Managed UK dedicated servers with 24x7x365 Support
Great Opportunity:: Join our Affiliate Program for FREE & earn up to £300 per sale.
Follow Us on Twitter and FaceBook
Reply With Quote

  #12 (permalink)  
Old 01-05-09, 05:21 AM
sysadmin's Avatar
Administrator
 
Join Date: Oct 2006
Posts: 295
Post

Quote:
Originally Posted by a1review View Post
Hi

Is there any time frame when FTP might be enabled?

Regards

Simon
As stated by James, the default/main FTP accounts have been disabled on the server permanently, but you can login to your cPanel account & create additional FTP accounts to perform the same file/folder operations.
Reply With Quote

  #13 (permalink)  
Old 01-05-09, 09:55 AM
new member
 
Join Date: Apr 2009
Posts: 2
Default

Thanks for letting me know
Reply With Quote

  #14 (permalink)  
Old 01-05-09, 03:37 PM
Sales Manager
 
Join Date: May 2006
Posts: 1,560
Send a message via AIM to James Send a message via MSN to James Send a message via Yahoo to James
Default

You're welcome.
__________________
WebHosting.UK.com :: Leader in Web Hosting
cPanel Hosting | Windows Hosting | Reseller Hosting | CLOUD HOSTING 100% Uptime
Dedicated Servers - Fully Managed UK dedicated servers with 24x7x365 Support
Great Opportunity:: Join our Affiliate Program for FREE & earn up to £300 per sale.
Follow Us on Twitter and FaceBook
Reply With Quote

  #15 (permalink)  
Old 01-05-09, 03:41 PM
Senior Member
 
Join Date: Jan 2007
Location: Dorset
Posts: 1,117
Default

I know heart internet suffered the same problem recently, they reset all the passwords and emailed the new passwords out which caused a few problems as you can guess, especially with clients who had many domains
Reply With Quote

Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump


All times are GMT. The time now is 05:05 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Copyright 2001-2010 Web Hosting UK. All rights reserved.
Web Hosting UK Forum





Site Map

Shared Cloud
Shared Cloud From £1

Affiliate Program
Earn up to £300 Per Sale

Dedicated Servers
Dedicated Server Hosting

Cloud Hosting
Cloud Server Hosting

Load Balanced Server
Load Balancing Server

VPS Hosting
Linux VPS Hosting

Windows VPS
Windows 2003 VPS

Zimbra Hosting
Zimbra Email Hosting

cPanel Hosting
Shared Linux Hosting

Windows Hosting
Shared Windows Hosting

Coldfusion Hosting
Windows Coldfusion Hosting

cPanel Reseller Hosting
Shared Windows Hosting

Windows Reseller
Windows Reseller Hosting

Email Web Hosting
Email Hosting

Semi-Dedicated Server
Semi-Dedicated Hosting

Remote Backup Plans
Offsite Backup Service


cpanel hosting
Knowledgebase Articles

Pre-Sales Question
Web Hosting FAQ's

Dedicated Hosting
Dedicated Server FAQ's

Virtual Private Servers
VPS Hosting

PHP MySQL Hosting
cPanel Hosting

Windows Hosting
ASP MSSQL Hosting

Domain Name
Domain registration FAQ's

CMS Hosting
CMS Hosting FAQ's

Payment Gateways
Payment FAQ's


Support Tutorials

cPanel Tutorials
cPanel Flash Tutorials

Wordpress Tutorials
Wordpress Flash Tutorials

Plesk Tutorials
Plesk Flash Tutorials

PhpMyadmin Tutorials
PhpMyadmin Flash Tutorials

Drupal Tutorials
Drupal Flash Tutorials

Mambo Tutorials
Mambo Flash Tutorials

Joomla Tutorials
Joomla Flash Tutorials

More Hosting Tutorials