Web Hosting News
  Home arrow Web Hosting News arrow Page 4 - cPanel, IE Security Flaws Exploited by...
Web Hosting Articles  
Web Hosting FAQs  
Web Hosting How-Tos  
Web Hosting News  
Web Hosting Security  
IBM® developerWorks 
Sun Developer Network 
Weekly Newsletter 
 
Developer Updates  
Free Website Content 
ASP Web Hosting  
ASP.NET Web Hosting 
Budget Hosting 
Coldfusion 
Colocation 
Mobile Linux 
APP Generation ROI 
E-Commerce Hosting 
Linux Web Hosting 
Managed Hosting 
Reseller Web Hosting 
Shared Hosting 
Small Business Hosting 
Virtual Private Servers 
Windows Web Hosting
 
 RSS  Articles
 RSS  Forums
 RSS  All Feeds
Write For Us Get Paid 
Request Media Kit
Contact Us 
Site Map 
Privacy Policy 
Support 
 USERNAME
 
 PASSWORD
 
 
  >>> SIGN UP!  
  Lost Password? 
WEB HOSTING NEWS

cPanel, IE Security Flaws Exploited by Hackers
By: Terri Wells
  • Search For More Articles!
  • Disclaimer
  • Author Terms
  • Rating: 5 stars5 stars5 stars5 stars5 stars / 5
    2006-10-18

    Table of Contents:
  • cPanel, IE Security Flaws Exploited by Hackers
  • The Set Up
  • The Fallout
  • And What About Microsoft?

  • Rate this Article: Poor Best 
      ADD THIS ARTICLE TO:
      Del.ici.ous Digg
      Blink Simpy
      Google Spurl
      Y! MyWeb Furl
    Email Me Similar Content When Posted
    Add Developer Shed Article Feed To Your Site
    Email Article To Friend
    Print Version Of Article
    PDF Version Of Article
     
     
    ADVERTISEMENT


    cPanel, IE Security Flaws Exploited by Hackers - And What About Microsoft?


    (Page 4 of 4 )

    We know that cPanel responded quickly to repair the flaw once the company was informed. But what about Microsoft, whose IE issue made up the second half of the problem? Well, the software giant releases patches for its software on a regular schedule, unless it’s something really critical. And at first, Microsoft didn’t seem to think this particular exploit was critical enough. “Attacks remain limited,” explained Microsoft’s Scott Deacon on the company’s Security Response blog. “There’s been some confusion about that, that somehow attacks are dramatic and widespread. We’re just not seeing that from our data, and our Microsoft Security Response Alliance partners aren’t seeing that at all either.”

    In the normal cycle of things, Microsoft would have waited until October 10 to release a patch for this vulnerability. In fact, the Zeroday Emergency Response Team (ZERT) released an unofficial patch. “We think it’s great that there are people out there working to help protect our customers,” Deacon noted, alluding to this group of veteran security researchers, “But as we’ve always said, we cannot endorse third party updates.”

    It took a little bit longer, but the software giant finally did post a patch, on September 26. Microsoft says that the patch not only takes care of the public security issue but also “additional issues discovered through internal investigations.”

    From a web hoster’s point of view, what happened has to be one of the scarier scenarios: two security holes in software created by two different vendors (only one of which needs to actually be used by the web host) being exploited together to attack your customers. With the amount of third-party software being used, it may become a more common scenario as well. We can only hope that proprietary software vendors become ever more responsive to their user’s needs and concerns, to help keep the damage from such an event from getting out of hand.


    DISCLAIMER: The content provided in this article is not warranted or guaranteed by Developer Shed, Inc. The content provided is intended for entertainment and/or educational purposes in order to introduce to the reader key ideas, concepts, and/or product reviews. As such it is incumbent upon the reader to employ real-world tactics for security and implementation of best practices. We are not liable for any negative consequences that may result from implementing any information covered in our articles or tutorials. If this is a hardware review, it is not recommended to open and/or modify your hardware.

       · Thanks for reading. For the sake of the web hosts affected, I was pretty horrified...
       · I wonder how many hosting companies haven't patch their cPanels?
     

    WEB HOSTING NEWS ARTICLES

    - The New FCC Regulator`s Mobile Plan
    - ICANN Ends Domain Tasting
    - Fake Security is Big Business
    - Microsoft Aims to Eliminate Piracy
    - Spam Increasing, and This Time it`s Personal
    - New Internet for Space, New Technologies to ...
    - FCC Frees White Space Spectrum for Wireless ...
    - An Old Trojan in New Clothing
    - DNS Flaw Causes Global Panic
    - ICANN Strives to Stop GoDaddy and Others fro...
    - No Winners in the Battle for the Internet
    - ICANN Decides To Expand Internet
    - Other Methods of the RBN
    - Around the Campfire with Google App Engine
    - DoS: No One is Safe






    © 2003-2009 by Developer Shed. All rights reserved. DS Cluster 4 Hosted by Hostway
    For more Enterprise Application Development news, visit eWeek