Banned apy67 Posted August 30 Banned Posted August 30 SUBJECT: SECURITY REPORT – POTENTIAL ACCOUNT IMPERSONATION / OWNERSHIP VERIFICATION WEAKNESS ⚠️ SECURITY NOTICE – PLEASE KEEP THIS REPORT PRIVATE ⚠️ IMPORTANT: This report contains details about a potential security weakness involving account ownership verification. Because the potential issue described below could possibly be abused if the details are publicly available, I kindly ask that this report be kept PRIVATE and NOT made publicly visible on the support forum while it is being investigated. Please restrict access to this report to HelioHost staff/security personnel who need to review it. I have intentionally NOT tested this potential vulnerability against another user's account, because I do not want to cause any unauthorized changes or harm. I am reporting it based on my analysis only. If the report is currently visible publicly, I would greatly appreciate it if you could hide or close it from public view before reviewing the technical details below. Thank you for understanding. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Hello HelioHost Security/Support Team, I would like to report a potential security weakness that I identified while analyzing the way account-related support requests are handled through the public HelioHost support forum. First, I want to make it clear that I have NOT attempted to exploit this issue against another user's account, and I have NOT attempted to make any unauthorized changes, deletions, or modifications to anyone else's hosting account. This report is based entirely on my analysis of the publicly visible support forum and the possible relationship between publicly disclosed account information and the account ownership verification process used by support staff. I am reporting this because I believe the scenario may be worth reviewing from a security perspective. ━━━━━━━━━━━━━━━━━━━━ 1. SUMMARY ━━━━━━━━━━━━━━━━━━━━ The potential issue is that users sometimes provide identifying hosting information in public support forum posts. For example, a user may publicly provide information such as: Username: exampleusername Server: Johnny Domain: example.helio.st Because the support forum is publicly accessible, anyone can read this information. My concern is that if the support team uses information such as the hosting username, server name, and domain as part of the verification process for sensitive account requests, an unrelated person could potentially obtain those details simply by reading a public forum post. In that situation, knowledge of the account information would not necessarily prove that the requester is the legitimate owner of the hosting account. ━━━━━━━━━━━━━━━━━━━━ 2. POSSIBLE ATTACK SCENARIO ━━━━━━━━━━━━━━━━━━━━ The scenario I identified would work conceptually as follows: 1. A legitimate hosting customer creates a support topic on the public forum. 2. The customer includes account-related information in the post, for example: - Hosting username - Server name - Domain/subdomain - Other publicly visible account identifiers 3. Because the forum is public, another person can read the post and obtain those details without having access to the customer's hosting account. 4. The unrelated person could then create their own forum account and contact support. 5. If the support verification process relies primarily on the publicly available information to establish ownership, the unrelated person might potentially be able to present the same information and appear to be the legitimate account owner. 6. If support then performs a sensitive administrative action based on that information alone, the legitimate account could potentially be affected without the actual owner's knowledge or authorization. Again, I have NOT performed these steps against another user's account. This is the theoretical scenario I identified while analyzing the process. ━━━━━━━━━━━━━━━━━━━━ 3. WHY I BELIEVE THIS COULD BE A SECURITY ISSUE ━━━━━━━━━━━━━━━━━━━━ The important distinction here is between ACCOUNT IDENTIFICATION and ACCOUNT OWNERSHIP VERIFICATION. A username, server name, and domain can identify which hosting account a request refers to. However, if those details are publicly available on the support forum, they may not prove that the person making the request actually owns or controls that account. For example: "Username: exampleusername" can identify an account, but it does not necessarily prove: "I am the person who owns exampleusername." This becomes particularly important when the requested action is destructive or otherwise sensitive. A malicious user does not necessarily need to compromise the customer's password or hosting panel if publicly available information is accepted as sufficient proof of ownership. ━━━━━━━━━━━━━━━━━━━━ 4. POTENTIAL IMPACT ━━━━━━━━━━━━━━━━━━━━ If the scenario is possible under the current support verification process, the potential impact could include unauthorized administrative actions against a hosting account. Depending on what actions support staff are permitted to perform after verification, the impact could potentially include things such as: - Removing or modifying a domain - Changing account-related settings - Making other hosting configuration changes - Performing administrative actions requested by an impersonator I am not claiming that all of these actions are currently possible. I am specifically asking the HelioHost team to verify whether the current verification process prevents this type of impersonation before any sensitive account action is performed. ━━━━━━━━━━━━━━━━━━━━ 5. WHY THE PUBLIC FORUM IS RELEVANT ━━━━━━━━━━━━━━━━━━━━ I want to emphasize that I am NOT suggesting that the support forum being public is itself a vulnerability. A public support forum is expected to contain publicly readable posts. The security concern is the potential combination of two things: 1. Account-identifying information is publicly available. AND 2. The same information may potentially be used as evidence of account ownership when handling support requests. The first point alone is not necessarily a security problem. The second point is where the potential security weakness could exist. If publicly available information is sufficient to pass an ownership check for a sensitive administrative request, then an attacker may be able to impersonate a legitimate customer without actually gaining access to their account. ━━━━━━━━━━━━━━━━━━━━ 6. I HAVE NOT ATTEMPTED TO EXPLOIT THIS ━━━━━━━━━━━━━━━━━━━━ I want to be especially clear about this point. I have NOT: - Attempted to impersonate another customer - Attempted to contact support while pretending to be another customer - Attempted to delete or modify another user's domain - Attempted to access another user's hosting account - Attempted to bypass any authentication mechanism - Performed any unauthorized action I only identified the potential issue through analysis of how publicly available information could potentially interact with the support verification process. I intentionally did not test this against another user's account because doing so could cause real damage or unauthorized changes. I believe the safest approach is for HelioHost staff to review and test the scenario internally. ━━━━━━━━━━━━━━━━━━━━ 7. RECOMMENDED MITIGATION ━━━━━━━━━━━━━━━━━━━━ I would recommend ensuring that sensitive account actions cannot be authorized solely based on information that can be found in public forum posts. For example, the support process could require an additional ownership verification mechanism before performing sensitive actions. Possible approaches could include: - Verification through the email address associated with the hosting account - A verification code sent to the account owner's email - Verification through the hosting control panel - A request originating from an authenticated account session - Another secret or account-specific verification mechanism that is not publicly visible The important principle would be that knowing publicly available account information should not, by itself, be sufficient to authorize a sensitive administrative action. ━━━━━━━━━━━━━━━━━━━━ 8. REQUEST FOR SECURITY REVIEW ━━━━━━━━━━━━━━━━━━━━ I would appreciate it if the HelioHost team could review this scenario and determine whether the current support verification process already protects against it. There may already be additional verification steps that I am not aware of, in which case this report may simply highlight a potential misunderstanding of the process. However, if publicly available account information can actually be used as sufficient proof of ownership for sensitive account actions, I believe this would be worth addressing as a security issue. I am providing this report in good faith and with the intention of helping improve the security of the service and protect HelioHost customers from possible account impersonation. I have deliberately avoided testing the scenario against another customer's account because I do not want to cause any unauthorized changes or disruption. If necessary, I would be happy to provide additional details about the reasoning behind the potential vulnerability or clarify the scenario further. Thank you very much for taking the time to review this report and for handling it confidentially. Best regards, [Apy] 1
wolstech Posted August 30 Posted August 30 We require that the email address on the forum account match the email address of the hosting account for destructive operation such as a reset. It is only possible to have a single forum account with an email that matches a hosting account, and that account is created when the user creates the hosting account (or is automatically linked to the hosting account if an account with the email address already exists on the forum). Similarly, password resets and other sensitive operations are only sent to the email address on file for the hosting account. They cannot be requested to be sent to a different email address than the one that was provided on the hosting account. In addition, many questions and associated troubleshooting is actually performed by other users, not staff, hence why we ask for this information to be posted publicly. Please see https://wiki.helionet.org/FAQ#How_does_community-powered_support_work? for more information.
Banned apy67 Posted August 30 Author Banned Posted August 30 Thank you for the detailed explanation and clarification. I understand now that sensitive and destructive operations have an additional verification requirement through the email address associated with the hosting account, and that publicly visible information such as the username, server, and domain alone would not be sufficient for those operations. My concern came from seeing that some account-related information is publicly available on the support forum and from my own experience where I provided my username, server, and domain when requesting a domain addition without being asked for additional verification. I understand now that the verification requirements are different for sensitive or destructive operations, which addresses the main concern I had. I also understand why this information is requested publicly, especially since the HelioHost community helps with troubleshooting and support. I appreciate you taking the time to explain how the system works. I’m glad I reported the concern rather than attempting to test it against another user's account. Thank you again for the clarification and for looking into it. 1
wolstech Posted August 30 Posted August 30 No problem. Please let us know if you have additional concerns. 1
Guest abdalpabdalpS Posted August 31 Posted August 31 @wolstech Hello, my username is abdalpabdalp5. Can you delete my account for me, please? Thanks!
Banned apy67 Posted September 1 Author Banned Posted September 1 @wolstechThanks for the clarification. Just one thing I’d like to confirm: does the same email ownership verification also apply to hosting account actions such as deleting an existing hosting account or adding/creating a hosting account? I understand that sensitive operations require verification, but I’d like to know specifically whether those two actions are also protected by the same requirement. Thank you. 1
KazVee Posted September 9 Posted September 9 For concerns regarding this user and hosting account, see: https://helionet.org/index/topic/69244-solved-identity-theft/#findComment-307009 1
Recommended Posts