Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

[Req] Two-Factor Authentication + Recaptcha For VestaCP

General questions about VestaCP
Post Reply
  • Print view
Advanced search
4 posts • Page 1 of 1
xorro
Posts: 87
Joined: Sun Nov 13, 2016 3:11 pm
Contact:
Contact xorro
Website Skype

Os: CentOS 6x
Web: apache + nginx
[Req] Two-Factor Authentication + Recaptcha For VestaCP
  • Quote

Post by xorro » Tue Sep 11, 2018 8:05 pm

Well it's been a long time since people are using VestaCP more and more but when we search on internet people are afraid to use it sometimes just because lack of security on control panel login. I know we can use VestaCP fail2ban and ngx_http_limit_req_module to secure some stuff but that is not the proper solution for brute-forcing because if someone is attacking my server they might be using tons of proxies and when ngx_http_limit_req_module hits the limits mentioned in configurations users will start seeing 503 Error but what is server operator is away for a while or is on vacations? using ngx_http_limit_req_module and fail2ban will be a temporary solution and need someone to monitor the server and keep changing the limit in config file so websites can stay up all the time. Well i hope you guys will understand there are many possibilities. I am also not saying that Two-Factor or Captcha is the final solution to stop these attacks but at least it makes it much more harder for hackers/attackers to get in to admin panel.

I have seen feature adding submissions on bug reporting system but they have been left dead and never heard of these solution to be coming out. This is 2018 and We are still waiting for one of the best free vps control panel creators to add these both in vestacp so we can recommend this to others even if they have any concern about security they do not get a chance to deny the respect for this control panel.
Top

maman
Posts: 17
Joined: Mon Aug 27, 2018 3:05 pm

Os: CentOS 4x
Web: apache
Re: [Req] Two-Factor Authentication + Recaptcha For VestaCP
  • Quote

Post by maman » Thu Sep 13, 2018 4:19 am

Yes i agree with you. But that is not the solution which too annoying. A better idea is to make vesta admin panel accesible only from localhost and you can access it via ssh tunnel. That is much more safer than waiting for vestacp team release a bug fix (which will take way way way way way 100x to long for them to release it). And my suggestion do not use vestacp using the default setting. Because from my experience modifying vestacp to my own needs, vestacp has too many small bugs (non security related). Maybe this is because they support multiple OS. In order to fullfill that you need to make separate source code for each OS. Each OS needs some modification, so its hard to maintain multiple OS source code without doing some mistakes (bugs) especially when theres an major OS update some code needs to be modified again. Unlike cpanel they only focus on one OS (centos) so its easier to maintain. Maybe vestacp team should separate each OS development to specialized team below lead team. So its easier to maintain. Just my 2 cents.
Top

maxpostal
Posts: 88
Joined: Thu May 05, 2016 1:01 pm

Re: [Req] Two-Factor Authentication + Recaptcha For VestaCP
  • Quote

Post by maxpostal » Sun Sep 23, 2018 6:19 pm

Hi,

Is the any news about that idea?
Top

xorro
Posts: 87
Joined: Sun Nov 13, 2016 3:11 pm
Contact:
Contact xorro
Website Skype

Os: CentOS 6x
Web: apache + nginx
Re: [Req] Two-Factor Authentication + Recaptcha For VestaCP
  • Quote

Post by xorro » Thu Sep 12, 2019 10:40 pm

It's been a year but no news because current vestacp setup already have too many bugs and needs to be fixed and updated so i think developer do not have time to add new features. Or maybe not have even time to fix current bugs.
Top


Post Reply
  • Print view

4 posts • Page 1 of 1

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password