|
|||
|
cpanel file manager security vulnerability
|
|
|||
|
Quote:
You know, considering the original forum post referred to in the article seems to be missing, it's hard to say. My gut feeling is this would be big enough to warrant a "please remove your post while we fix this" request from cpanel. If it was simply mistaken, I'd expect a retraction/clarification post rather than removal. fwiw, I've disabled File manager on all my cpanel machines until we find out more. ![]() Edit: Interesting - I disabled file manager (whm -> packages -> feature manager -> disabled -> untick FM -> save), yet I can still access it through cPanel. WHM 10.8.0 - cPanel 10.8.1-S114 Last edited by /bin/bash.org; 02-28-2006 at 02:24 AM. |
|
||||
|
This was discussed some days ago and is fixed in EDGE if you check the changelog.
__________________
Jonathan Michaelson cPanel Forum Moderator Need your cPanel servers secured and tuned? cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf http://www.configserver.com |
|
||||
|
Quote:
__________________
Jonathan Michaelson cPanel Forum Moderator Need your cPanel servers secured and tuned? cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf http://www.configserver.com |
|
||||
|
Quote:
__________________
Jonathan Michaelson cPanel Forum Moderator Need your cPanel servers secured and tuned? cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf http://www.configserver.com |
|
|||
|
Well, I hope someone comes with a solution without having to upgrade to EDGE.
How can we see which users have used file manager previously? (which would make those accounts exploitable by everyone, right?) My cpanel logs don't go back so far. As a temporary fix I chmodded the cpanel WysiwygPro directory to 000. Last edited by jamesbond; 02-28-2006 at 06:00 PM. |
|
|||
|
Quote:
|
|
||||
|
Quote:
__________________
Jonathan Michaelson cPanel Forum Moderator Need your cPanel servers secured and tuned? cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf http://www.configserver.com |
|
|||
|
Quote:
![]() Anyway, I appreciate that you are just the messenger, so I'll take this up directly with cPanel. As an aside, chirpy - now there's a Spanish forum, how about a security forum with date stamped topics so we can easily see what issues are current and those resolved or with workarounds available? I can't imagine what it's like for you, but I find it tiring chasing 6 threads around 4 forums on the same topic, only to see answers like "Oh, we discussed that a few days ago" without any reference to what/where/how/etc. Maybe we can keep security discussions in one place and reduce redundancy? --Matt ;^] |
|
|||
|
I think the deficiencies in the CPanel changelog are well documented. I don't have a problem with the current changelog, but I think it would also be helpful to have a changelog for the other versions as well (Current, Release, Stable). This way you know what issues are resolved in your current version. As it stands now, if a new Current is released, you don't really know if it contains the fix for this exploit or not, its just more or less a guess.
Perhaps this should be logged in Bugzilla as an enhancement request. However, I do see where there are some similar requests in Bugzilla that appear to be somewhat dated. I know this post is somewhat off-topic and I apologize for that. If concerns about the ChangeLog warrant further discussion, I would recommend that someone post a new topic rather than take this thread further off course. I posted in this thread because I thought it was important to bring to the attention some of the confusion over the current ChangeLog and why some users are confused as to what security/bug fixes have been applied to their current CPanel version. |
![]() |
| Thread Tools | |
| Display Modes | |
|
|