Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 11 of 11
  1. #1
    Member
    Join Date
    Jan 2002
    Location
    UK
    Posts
    248

    Default CERT Advisory CA-2002-19 Buffer Overflow in Multiple DNS Res

    Does this effect our cpanel installs? if so, any idea when the update is going in (or has it already?).

    Cheers,
    Andy

  2. #2
    itf
    itf is offline
    Member
    Join Date
    May 2002
    Posts
    626

    Default

    YES! Our Cpanel servers use BIND 9.2.1 which is vulnerable

    BIND 9 contains a copy of the BIND 8.3.x resolver library (lib/bind). This will be updated with the next BIND 9 releases (9.2.2/9.3.0) in the meantime
    Please use messengers to contact me:
    MSN: patrickay@msn.com
    AIM: PatrickITF

  3. #3
    Member
    Join Date
    Aug 2001
    Posts
    839

    Default

    Just keep &security updates& enabled within your panels........... (in the update section of WHManager)
    That's by far the most important, and you should never circumvent that no matter how much you think auto-updates are going to ruin your life.

    In this case, you only get daemon patches that defend your system against the latest exploits. The day that redhat constructs an rpm to patch an exploit, you can bet darkorb will have it in the rpmupdate that very night. And until an rpm is released, if not immediately, in most cases cpanel will release a patch (whatever procedure is required to secure the daemon without a version update), until the rpm or source is tangible to the public.

    That's been my experience, anyway.
    ..............................


    http://www.fastservers.net/

    travis@fastservers.net
    ..............................

  4. #4
    Member
    Join Date
    Jun 2002
    Posts
    78

    Default

    Yes, just got the SSH rpm update from layer2.cpanel.net

    This thing rocks

  5. #5
    itf
    itf is offline
    Member
    Join Date
    May 2002
    Posts
    626

    Default

    Cpanel is one of the bests; as &feanor& wrote wait for the latest update from Red Hat but if you are under attack you can install bind 8.3.3 which is not vulnerable

    But if you are not just wait
    Please use messengers to contact me:
    MSN: patrickay@msn.com
    AIM: PatrickITF

  6. #6
    Member
    Join Date
    Jun 2002
    Posts
    78

    Default

    Looks like the attack has started :-(

    BIND is the worst open source software I have dealt with. So many vulnerabilities so often.

    I like tinydns. it rocks

  7. #7
    Member
    Join Date
    Dec 2001
    Posts
    224

    Default

    will running redhat &up2date& have problems with cpanel?
    www.tys.us
    TYS-HR Datacenter
    100% uptime power & feed
    Colocation/Dedicated/Managed

  8. #8
    Member
    Join Date
    Aug 2001
    Posts
    839

    Default

    That all depends how you fine tune the up2date config. If you go too far, you can begin updating packages that may actually affect your cpanel install, as the updates will come from redhat instead of cpanel's storehouse of packages they have deemed worthy to work with the cpanel software.

    I would recommend not using up2date on a cpanel machine so you don't CROSS the STREAMS
    (ghostbusters)

    But perhaps darkorb can answer this more explicitly?
    up2date does have its uses, its just that cpanel already has a mechanism like this built in.
    ..............................


    http://www.fastservers.net/

    travis@fastservers.net
    ..............................

  9. #9
    Member
    Join Date
    Mar 2002
    Posts
    67

    Default

    Hi

    How could I know the auto update kicked off ? it was turned off couple of days then I turned it on when I read about that ssh bug.

    And how do I do it manualy, just in case ?

  10. #10
    Member
    Join Date
    Dec 2001
    Posts
    224

    Default

    feanor, thankx
    www.tys.us
    TYS-HR Datacenter
    100% uptime power & feed
    Colocation/Dedicated/Managed

  11. #11
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default

    netgrek, you can make the updates run manualy in the panel. Scroll down to the bottom area, or log in as root and run /scripts/sysup and /scripts/rpmup


    Bind is by far the worst most buggy'est service i think i have ever ran into. it's rediculis. We run tinydns on our main nameservers here at OC it would be nice to see cpanel switch.
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

Similar Threads & Tags
Similar threads

  1. Replies: 3
    Last Post: 08-30-2010, 02:02 PM
  2. multiple domains to use servers ssl cert
    By maggot96 in forum New User Questions
    Replies: 2
    Last Post: 04-09-2009, 06:42 PM
  3. Replies: 5
    Last Post: 08-15-2006, 06:28 PM
  4. Buffer Overflow Attemp?
    By fizz in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-07-2004, 10:54 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube