zPanel hacked
Posted by: TimW on 05/16/2013 12:33 PM
[
Comments
]
Looking for the official web site for the web hosting interface zPanel. You won't find it because it was hacked in an attack when a member of the support team swore at a user on the forum.
A forum member by the name of joepie91_ posted details of the sites vulnerabilities. He explained that specially prepared templates can be used to execute commands on the server with root privileges and called zPanel "the most insecure hosting panel with any significant userbase" that he had ever seen.
A member of the support team, known as PS2Guy, replies with calling joepie91_ a "fucken little know it all". He then challenged the accuser to try to hack the server. Only administrators can upload templates, making the vulnerability more difficult to exploit.
This led to anger, especially in reddit's security community /r/netsec, which led then to someone taking the challenge literally. The target was the open source main server. At the moment, a visit to the domain only brings up a test page for the Apache web server. The culprit and their method for compromising the server are still unknown.
A member of the support team, known as PS2Guy, replies with calling joepie91_ a "fucken little know it all". He then challenged the accuser to try to hack the server. Only administrators can upload templates, making the vulnerability more difficult to exploit.
This led to anger, especially in reddit's security community /r/netsec, which led then to someone taking the challenge literally. The target was the open source main server. At the moment, a visit to the domain only brings up a test page for the Apache web server. The culprit and their method for compromising the server are still unknown.
Comments