is this fixed in the latest stable version ?
is this fixed in the latest stable version ?
No cpanel servers should be vulnerable to this anymore. Cpanel themselves hacked those that were in order to patch them.Originally posted by WCW Fan
is this fixed in the latest stable version ?
But it is old news. This exploit was posted and patched along with the "lost password" hack.Originally posted by Domenico
EDIT: this is not about the 'lost password' hack! Read carefully...
Does it take too much effort to refer to the "latest update" by its number? There are THREE versions EDGE, RELEASE and STABLE, each with numbers that appear in the upper right hand corner. It would be a lot simpler to use them rather than having to poke around to find out what the LATEST is as of when.This has been patched in latest forced update
I think that people on this forum deserve that cpanel officaly say to us wich version are secure and wich are not.
I had before day's rootkit and I spend hell-weekend just becouse I didn't know that there is autorootkit for cpanel.
I think that in any case custumers have right to know about all problems, If we continue to keep things just for our selves, and not share information we may just forgot about security and give keys of our servers to people who know better than us wich version are vurnelable or wich software have bugs.
Signed,
Dzevad Hadzic
8.6.0build31 though 9.1.0build40 are the builds with the security problems.Originally posted by zex
I think that people on this forum deserve that cpanel officaly say to us wich version are secure and wich are not.
I had before day's rootkit and I spend hell-weekend just becouse I didn't know that there is autorootkit for cpanel.
I think that in any case custumers have right to know about all problems, If we continue to keep things just for our selves, and not share information we may just forgot about security and give keys of our servers to people who know better than us wich version are vurnelable or wich software have bugs.
Thank you for fast replay. This is very helpful.
Signed,
Dzevad Hadzic
Uh, autorootkit?Originally posted by zex
... <snip> ... didn't know that there is autorootkit for cpanel ... <snip> ...
What is autorootkit?
-- Arthur Cronos from Voltos
=================================================
The Bloggard, Un Hombre Muy Blogisto -- http://www.bloggard.com
Your loch ness monster, your yeti, your bigfoot. Bah! I've seen worse.
=================================================
Please don't be a dumb ass!Originally Posted by thaphantom
Security through obscurity isn't.
The information is public domain already. And telling Admins how to test to see if their own system in vulerable - is an important way for them to check the vendor has fixed the problem.
Dasher
Is there a date on a principle?Originally Posted by thaphantom
I was referring to the general principle of full disclosure.
Your rule #2 applies...