osCmax v2.5 User Manual
Results 1 to 5 of 5

web server uses cleartext HTTP Basic authentication

This is a discussion on web server uses cleartext HTTP Basic authentication within the General Topics & Chit Chat forums, part of the Community category; Hello, One of my site's PCI scan has a vulnerability of 3. The issue is that the web server uses ...

      
  1. #1
    Member
    Join Date
    Sep 2008
    Posts
    32
    Rep Power
    0


    Default web server uses cleartext HTTP Basic authentication

    Hello,
    One of my site's PCI scan has a vulnerability of 3. The issue is that the web server uses cleartext HTTP Basic authentication. How can I fix this? Any advice is greatly appreciated. Thank you! This is the complete vulnerability description:

    Description: web server uses cleartext HTTP Basic authentication (/) Severity: Potential Problem Impact: Poor authentication practices may leave the web application vulnerable to authentication attacks. Background: Some web applications perform authentication by requiring a user to enter a login and password into an HTML form. This type of authentication is achieved us ing the HTML INPUT element with the type attribute set to password. Resolution To use HTML form-based authentication more securely in web applications, do the following: Remove the value attribute from the INPUT tag corresponding to the password field. Submit all forms to an SSL-enabled (https) service using the form's action attribute. Place all protected web directories on an SSL-enabled (https) service. Use the autocomplete="off" attribute in the INPUT tag corres ponding to the password field. Vulnerability Details:
    Service: 2077:TCP Received: WWW-Authenticate: Basic realm="cPanel WebDisk"
    Last edited by lindsay; 12-13-2010 at 01:54 PM. Reason: misspelling

  2. #2
    osCMax Development Team
    Join Date
    Nov 2002
    Location
    Orlando
    Posts
    433
    Rep Power
    14


    1 out of 1 members found this post helpful.

    Default Re: web server uses cleartext HTTP Basic authentication

    That is a WHM/Cpanel server setting that the webhost/server admin controls and 2077 isn't a secure SSL log in. 2078 is secure https log in for that. Cpanel has secure ports and non secure but if you're running PCI scans then you probably want to be on a more secure server. The secure log ins are 2078,2083,2087 on Cpanel.
    John

  3. #3
    Member
    Join Date
    Sep 2008
    Posts
    32
    Rep Power
    0


    Default Re: web server uses cleartext HTTP Basic authentication

    Hello,
    Is this something that they may be able to adjust? I will speak with my hosting company and see what they can do. Thank you for your help! Have a great December!
    Lindsay

  4. #4
    osCMax Development Team
    Join Date
    Nov 2002
    Location
    Orlando
    Posts
    433
    Rep Power
    14


    Default Re: web server uses cleartext HTTP Basic authentication

    If I were you I would look for a host that is concerned with PCI compliance without you having to push them to it. Your host may have a better suited server. Budget hosting is one of the reasons PCI compliance is done. You can find hosts that are PCI compliant and FYI Michael has AAbox hosting so you could talk to him.

    Bottom line is don't penny pinch on hosting because it will bite you in the...
    John

  5. #5
    Member
    Join Date
    Sep 2008
    Posts
    32
    Rep Power
    0


    Default Re: web server uses cleartext HTTP Basic authentication

    I will keep his hosting company in mind. It would be nice to have all of that support. Thank you for the advice!

Similar Threads

  1. Replies: 14
    Last Post: 12-18-2009, 08:43 AM
  2. Failed to Get Basic Authentication Headers/Google Checkout
    By jasper0 in forum osCmax v2 Customization/Mods
    Replies: 3
    Last Post: 10-28-2007, 07:57 PM
  3. SEO, http and https problem
    By subtleinstrument in forum osCMax v2 Features Discussion
    Replies: 3
    Last Post: 04-02-2007, 08:31 AM
  4. http://www.adoptafurby.com Thanks!!!
    By r_fulton13 in forum osCmax v1.7 Discussion
    Replies: 0
    Last Post: 01-19-2006, 03:51 AM
  5. HTTP Error 403 - Forbidden
    By dulceybranch in forum osCommerce 2.2 Installation Help
    Replies: 0
    Last Post: 11-28-2005, 09:53 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •