July 29th, 2006, 07:52 PM
Security Alert: cPanel doesn't require username to log in...
I posted this here because I figure a lot of you use cPanel at your own websites. I do myself, so hopefully this is useful information to some of you.
I got an email yesterday on bugtraq claiming that to log into a cPanel account you do not need a username, only the password. I tried this out on mine, and it seems to be true. I left the username field blank, and only typed my password, and it logged me in just fine.
I'm not sure that there is an updated version of cPanel out yet to use, but you all should be aware of this, as it makes the breaking in significantly easier for an intruder, especially if (like me) you use a not-so-easily-guessed username.