Results 1 to 4 of 4

Thread: mywebpayment security concerns

  1. #1
    Member Newbie tamlyn's Avatar
    Join Date
    Aug 2005
    Location
    Manchester, UK
    Posts
    67

    Default mywebpayment security concerns

    I logged into mywebpayment.com to check when my vps was due for renewal I was surprised to see my root password displayed in the account details. The problem is that if someone has access to my computer, they have access to my email and if they have access to my email they have access to the mywebpayment interface (since they can get a new password sent out) which then gives them access to my VPS.

    Admittedly if someone has access to my email, that's worrying in itself and if I were to lose my laptop the first thing I would do is change all my passwords but I still don't think the root password should be displayed online in this fashion.

    It's not going to keep me awake at night but I thought I would mention it anyway.
    "They think they've tricked you. And then they have."

  2. #2
    Forum Administrator Power Poster Lyle@Spry's Avatar
    Join Date
    May 2005
    Posts
    455

    Default

    Valid concerns.

    You can change the root password on your server with passwd (while logged in as root). This does not update our information displayed at MyWebPayment.com, so the password displayed would be incorrect. (Which is why we'll sometimes ask for your root password to be able to access your server for troubleshooting.)

  3. #3
    Member Newbie tamlyn's Avatar
    Join Date
    Aug 2005
    Location
    Manchester, UK
    Posts
    67

    Default

    Ah thanks. The root password's due for a change anyway. So what is the password in mywebpayments?
    "They think they've tricked you. And then they have."

  4. #4
    Forum Administrator Power Poster Lyle@Spry's Avatar
    Join Date
    May 2005
    Posts
    455

    Default

    That password is the root password requested during signup. Changing it on the server just doesn't send it back to MyWebPayment for update.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •