Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    Dec 2001
    Posts
    185

    Default crack or bug

    on one box we have reseller which DOES NOT have shell access, we usually dont give shell access to any body :-)

    he resells predefined packages which they dont have shell access either.

    we found out he had setup an account recently trough his control panel and packages, which has shell access.

    well, there is only one 0 UID in passwd and ps is fine no sign for any crack or hack,

    Then i found out there are two other users that they have shell access too, they are created with root user,

    seems like some thing going on there...

    also it would be nice to have an option in modify account ( WHM ) to grant shell access or disable it.

    any idea on the problem?

    Thanks,
    ~ Ehsan
    Do You Have a Hosting Business?
    If you can handle more clients list your business at: www.myserver.us

  2. #2
    Member
    Join Date
    Aug 2001
    Posts
    130

    Default

    If you want to disable all shell access, just modify your packages and it will update all accounts with those packages.

    If you want to easily switch between has shell or does not have shell you could create two packages with the same stats EXCEPT one has shell access and one doesnt.

    Then you can turn it off and on.

    Hope that helps you
    Zach

  3. #3
    Member
    Join Date
    Dec 2001
    Posts
    185

    Default

    well,

    thank you for reply

    actually that is not the problem, you can grant access or get shell access from a user manually from shell.

    problem is security issue, how thoes accounts have shell access while they are on no shell access package.
    ~ Ehsan
    Do You Have a Hosting Business?
    If you can handle more clients list your business at: www.myserver.us

  4. #4
    Member
    Join Date
    May 2002
    Posts
    249

    Default

    Ehsan, in the reseller center, make sure you have these options checked/unchecked..

    [] Allow Creation of Packages with Shell Access
    [] All Features (warning: root access)
    [X] Never allow creation of accounts with shell access
    [] Account Modification (warning: this will allow circumvention of account creation limits, give shell access, dedicated ips, etc)

  5. #5
    Member
    Join Date
    Dec 2001
    Posts
    185

    Default

    Saeed,
    I have them all :-)

    Nobody has shell access at all... getting scary...
    ~ Ehsan
    Do You Have a Hosting Business?
    If you can handle more clients list your business at: www.myserver.us

  6. #6
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    so did we find out if this was a &crack or bug& or a &crack in a bug& or maybe it is a &bug in a crack& ?
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  7. #7
    Member
    Join Date
    Dec 2001
    Posts
    185

    Default

    well,
    we are sure it is a bug, but what kind we dont know yet
    might be bee or fly or something like that :-)

    hopefully it is not benbug (new bug created by benladen)
    hehe

    ok, seriously, there is no answer yet, no guess for crack, we checked many things like possible changes in ps command or other monitoring parts.
    those accounts have never loged in to shell.
    It is a bug somewhere...
    ~ Ehsan
    Do You Have a Hosting Business?
    If you can handle more clients list your business at: www.myserver.us

Similar Threads & Tags
Similar threads

  1. Is someone peeking in ????Someone is trying to crack server!!!
    By atul in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 07-14-2004, 10:55 AM
  2. HACK CRACK! important!!
    By Creazioni in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 04-14-2003, 12:15 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube