Skip to main content

My WHM account access was stolen

Comments

8 comments

  • arlindmurati
    I'm not sure if I understood correctly, however if someone has your WHM access they shouldn't be able to buy something from the cPanel store as they would need your cPanel store logins, or they would require your login details for the billing platform of your host to do any harm.
    0
  • cPRex Jurassic Moderator
    I agree with @arlindmurati1 - while having the WHM access stolen is never good, and would necessitate a migration to a new machine that is secure, they would not be able to make purchases without also having the cPanel store account.
    0
  • arlindmurati
    I agree with @cPRex a migration is an immediate action you should take, even better from an offsite backup, after restoring please make sure to change WordPress login details, database names, database users passwords, cPanel passwords, disable mysql remote connection etc..
    0
  • rinrikun2021
    Hello, thank you all for your help What if the WHM account is linked to the Cpanel Store account? Is it still possible?
    0
  • cPRex Jurassic Moderator
    I suppose that could be an issue if they had already been linked before, but usually when you submit a support ticket it does ask you to log in again.
    0
  • rinrikun2021
    So, all purchases must use the cpanel store website, right? Is it possible to make a purchase on my domain or IP address? My way to view connected accounts is using the "Manage External Authentications" menu, correct?
    0
  • cPRex Jurassic Moderator
    All purchases do need to go through the cPanel store, whether that happens directly from the store URL or through the WHM interface. I'd be much more concerned about the server being compromised and getting the data migrated than of a user making random purchases on your account. "Manage External Authentications" is used for tools that are allowed to log in to your server. You can find more details on that here: Manage External Authentications | cPanel & WHM Documentation
    0
  • rinrikun2021
    Thank you for your concern. But this is a server for learning. Even if the contents are damaged, it's not a problem.
    0

Please sign in to leave a comment.