Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 2 of 2
  1. #1
    Member
    Join Date
    Mar 2004
    Posts
    117

    Default clustering security risks

    How does cpanel's multiple-server clustering feature affect the security of each of the individual clustered servers? For example, if one server in a cpanel cluster is rooted has cpanel's clustering feature ever been used to take down the other servers in the cpanel cluster?

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    The DNS clustering feature connects between servers using the WHM secure port (2087) and authenticates using the remote systems Remote Key. It doesn't use root password authentication. That said, once you have a remote servers Remote Key you can access many root functions within WHM on that server using a scripting language such as perl or PHP.

    I guess that any mechanism that allows you access between servers is going to have inherent security issues. I've certainly never heard of a compromise in this fashion though. While the risk might be there, it's probably very small indeed and since clustered servers are most likely maintained by the same person, the risk of a root compromise on one server could well be the same on the others anyway.

    Personally, I wouldn't worry about it too much. Just be sure to have good security and tripwire procedures in place to detect a root compromise, should you suffer one, asap.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. dns clustering security flaw
    By optize in forum cPanel and WHM Discussions
    Replies: 25
    Last Post: 01-15-2010, 07:42 PM
  2. security risks with cron jobs
    By mher in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 04-29-2006, 10:32 AM
  3. What are the risks of installing non-cPanel apps?
    By wa7son in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-29-2005, 12:01 PM
  4. Risks of SSH
    By dan_c in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 07-25-2005, 04:36 PM
  5. Shared Scripts... Security Risks?
    By Miso in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 07-23-2003, 01:16 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube