Hi all,
i would like to ask this feature cause i think is really important for security environment.
Right now each user of web server that run CGI or PHP can use a CGI shell or PHP shell to browse in file system. You can disable PHP functions but NOT CGI's ones.
Of course linux permissions does not let him go everywhere BUT that user can read configurations file, settings, log and so on. He can also for example upload a self-compiled binary of nmap or local exploit and try to gain root access.
I think this is really a big problem not yet and well understood.
I suggest you to use sbox (sbox: Put CGI Scripts in a Box) that looklikes a good start. It is fast, light and secure.
I hope you can realize that security side is really something to take much care of.
Oh, of course THANK YOU for all have you done until now![]()
It's one year that we use WHM/cPanel and software is good ok.. but helpdesk is BEST helpdesk in our universe, i am sure
I do not know other universe.. but we are lucky to have you
Really we try to take example from your helpdesk quality and copy same quality for our customers.
Best regards



LinkBack URL
About LinkBacks

Reply With Quote




