I thought I would share a security tip when selecting the 'Password Protection' cpanel feature.
Although there is no indication of this on the site, passwords created through the 'Password Protection' feature is actually limited to eight (8) characters. Anything after eight (8) characters will just be ignored! This is not a flaw of cpanel but a limitation of .htaccess files.
You can test this out yourself:
1. Use the 'Password Protection' feature to protect a directory using the password: 12345ABCDEF
2. Now browse to that directory and use the password:
12345ABC
And it will work!
3. Now also try the same thing again using the password:
12345ABCXXXXXX
And it will work!
So when selecting passwords, remember only the first eight (8) characters count! (Your 'Superman830382' password might not be that secure against brute force dictionary attacks after all!)
Hope you enjoyed this tip.


LinkBack URL
About LinkBacks



Reply With Quote

Bookmarks