cpanel

cPanel Security Hole Exploited in Wild

Tagged in

Netcraft: in reflecting to a previous report where HostGator sites were hacked to distribute IE exploits, HostGator responded saying that there is a bad security hole in cPanel that is currently wildly distributed.

Hackers gained access to HostGator’s servers late Thursday and began redirecting customer sites to outside web pages that exploit an unpatched VML security hole in Internet Explorer to infect web surfers with trojans. The existence of the new “0-day” exploit of cPanel leaves a large number of hosting companies vulnerable to similar attacks until they install the patch. The riusk is mitigated somewhat by the fact that it is a local exploit, meaning any attack on a host must be launched from an existing account with cPanel access.