{"id":4740,"date":"2021-07-16T09:23:53","date_gmt":"2021-07-16T15:23:53","guid":{"rendered":"https:\/\/www.whitefirdesign.com\/blog\/?p=4740"},"modified":"2021-07-16T09:23:53","modified_gmt":"2021-07-16T15:23:53","slug":"godaddy-hosting-phpmyadmin-on-server-with-broken-encryption-with-f-grade-from-ssl-labs","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2021\/07\/16\/godaddy-hosting-phpmyadmin-on-server-with-broken-encryption-with-f-grade-from-ssl-labs\/","title":{"rendered":"GoDaddy Hosting phpMyAdmin on Server With &#8220;Broken Encryption&#8221; With F Grade From SSL Labs"},"content":{"rendered":"<p>One telling example of the web security industry&#8217;s lack of concern for security is how web host GoDaddy has continued to have rather poor security while first being partnered with one web security company, SiteLock, and then owning another one, Sucuri.<\/p>\n<p>An example of that poor security came up a few months ago while we were dealing with a hacked website where <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2021\/04\/05\/sucuri-claims-to-know-the-most-common-cause-of-website-hacking-despite-not-determining-how-they-are-hacked\/\">Sucuri had not properly secured the website<\/a>. We meant to post about that at the time, but then forgot about it until we were dealing with another hacked website with <a title=\"Hacker Impersonated GoDaddy When Hacking GoDaddy Hosted WordPress Websites\" href=\"https:\/\/www.whitefirdesign.com\/blog\/2021\/07\/12\/hacker-impersonated-godaddy-when-hacking-godaddy-hosted-wordpress-websites\/\">a GoDaddy connection worth posting about<\/a>.<\/p>\n<p>While working on the hacked website, we accessed the phpMyAdmin database administration tool that GoDaddy provided and found a situation we can&#8217;t recall seeing before with a web host. That would be the SSL encryption was &#8220;broken&#8221; on the server hosting phpMyAdmin.<\/p>\n<p>If you access that in Google&#8217;s Chrome web browser the connection is listed as &#8220;Not Secure&#8221;:<\/p>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/not-secure.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-4751\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/not-secure.png\" alt=\"\" width=\"366\" height=\"36\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/not-secure.png 366w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/not-secure-300x30.png 300w\" sizes=\"auto, (max-width: 366px) 85vw, 366px\" \/><\/a>You are warned that &#8220;Your connection is not fully secure&#8221; and that:<\/p>\n<blockquote><p>This site uses an outdated security configuration, which may expose your information (for example, passwords, messages, or credit cards) when it is sent to this site.<\/p><\/blockquote>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/your-connection-is-not-fully-secure.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-4752\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/your-connection-is-not-fully-secure.png\" alt=\"\" width=\"607\" height=\"330\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/your-connection-is-not-fully-secure.png 607w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/your-connection-is-not-fully-secure-300x163.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/a><\/p>\n<p>When looking at the Technical Details of that issue with Firefox, it states:<\/p>\n<blockquote><p>Broken Encryption (\u200bTLS_RSA_WITH_AES_128_CBC_SHA, 128 bit keys, TLS 1.0)<\/p><\/blockquote>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/technical-details.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-4753\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/technical-details.png\" alt=\"\" width=\"549\" height=\"91\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/technical-details.png 549w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/technical-details-300x50.png 300w\" sizes=\"auto, (max-width: 549px) 85vw, 549px\" \/><\/a>If you run that <a href=\"https:\/\/www.ssllabs.com\/ssltest\/analyze.html?d=p3nlmysqladm001.secureserver.net\">address through the SSL Labs tool<\/a>, the server gets an F grade:<\/p>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/ssl-labs-results.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-4754\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/ssl-labs-results.png\" alt=\"\" width=\"1026\" height=\"812\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/ssl-labs-results.png 1026w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/ssl-labs-results-300x237.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/ssl-labs-results-768x608.png 768w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2021\/07\/ssl-labs-results-1024x810.png 1024w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/a><\/p>\n<p>The domain name being used for that insecure server, secureserver.net, which isn&#8217;t an accurate name.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>One telling example of the web security industry&#8217;s lack of concern for security is how web host GoDaddy has continued to have rather poor security while first being partnered with one web security company, SiteLock, and then owning another one, Sucuri. An example of that poor security came up a few months ago while we &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2021\/07\/16\/godaddy-hosting-phpmyadmin-on-server-with-broken-encryption-with-f-grade-from-ssl-labs\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;GoDaddy Hosting phpMyAdmin on Server With &#8220;Broken Encryption&#8221; With F Grade From SSL Labs&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[63],"class_list":["post-4740","post","type-post","status-publish","format-standard","hentry","category-bad-security","tag-godaddy"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/4740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=4740"}],"version-history":[{"count":6,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/4740\/revisions"}],"predecessor-version":[{"id":4755,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/4740\/revisions\/4755"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=4740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=4740"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=4740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}