Skip to main content

App for Android bypassing 2FA

Comments

8 comments

  • Infopro
    I've removed your link, that app is not affiliated with cPanel. This is the official cPanel app on googleplay:
    0
  • ijsaul
    Thank you, I'm certainly aware that the app I posted was not affiliated with cPanel. I'm wondering how it is possible that this application is bypassing what I thought was a requirement for login, namely 2FA. This seems like a security concern to me.
    0
  • Infopro
    TFA is not enabled by default, you enable it if you wish to use it. Two-Factor Authentication for WHM - Version 76 Documentation - cPanel Documentation
    0
  • ijsaul
    It is enabled, and has been a requirement for login on this server. What I'm saying is that this application is bypassing my enabled 2FA. How is bypassing 2FA possible.
    0
  • Infopro
    I can't answer that. I don't use the app or have an android to test to confirm the issue from here. Please feel free to open a ticket directly to cPanel Technical Support if you suspect and issue with Two-Factor authentication on your server.
    0
  • ijsaul
    I understand. Thank you for the direction. You may want to leave a link to the application with a note, as this app may be a security concern to others, and having this information out there would be useful. I'll explore with support and provide follow up later on.
    0
  • Infopro
    Please do. Thanks! I think removing the link from your post is best, no need to make it any more available than it might be otherwise.
    0
  • cPanelMichael
    Hello @ijsaul, You'll need to access WHM >> Configure Security Policies to extend the Two-Factor Authentication security policy to API requests. This will ensure it's enforced for third-party applications that make use of API calls for login purposes. You can read more about this option at:
    0

Please sign in to leave a comment.