Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 11 of 11
  1. #1
    rnh
    rnh is offline
    Member
    Join Date
    Apr 2003
    Posts
    118

    Default HOLD UP... NO CHROOT in Cpanel? WTF?

    Am I just missing something or is Cpanel running websites on servers in a NON Chroot environment?

    I just installed Cpanel yesterday on a new server switching over from Ensim because I wanted something more secure since Ensim is so slow to update patches, but if Cpanel is running virtual hosting where the users have access to browse through each other's files and the other files on the server then that is just ridiculous.

    Are there hosts out there actually running virtual hosting that's not a chroot environment?

  2. #2
    Member Nico's Avatar
    Join Date
    Dec 2001
    Location
    Edmond, OK
    Posts
    233

    Default

    You might look into enabling Jail Shell from WHM. That is supposed to prevent that.

  3. #3
    rnh
    rnh is offline
    Member
    Join Date
    Apr 2003
    Posts
    118

    Default

    ok thanks, I haven't had too much time to look around through this yet as I've only had Cpanel for a day.

    I'm not hosting people but I am sharing my server with a few people to reduce costs but I don't trust them enough to let them run on the same server without Chroot.

    I haven't seen enable Jail shell in WHM yet... any clues on where it's at in there? =) I'll keep looking and reading though, thanks.

    I was about to start setting up chroot and jails myself manually but it seems like Cpanel doesn't like you making changes without it from shell.

  4. #4
    Member Nico's Avatar
    Join Date
    Dec 2001
    Location
    Edmond, OK
    Posts
    233

    Default

    Check in "Account Functions" and it's the 3rd one from the bottom in the Xskin theme anyway

  5. #5
    Member
    Join Date
    Oct 2001
    Posts
    651

    Default

    In WHM, look for a link called "Manage Shell Access" or something similar. You can enable shell, disable shell, or enable jail shell on a per account basis from there.
    Marty Hoskins
    TLC Web Enterprises

  6. #6
    rnh
    rnh is offline
    Member
    Join Date
    Apr 2003
    Posts
    118

    Default

    Hmm, I forgot to mention I'm running FreeBSD (4.7)...

    WHM 6.0.0
    Cpanel 6.0.0-S113

    Just installed the night before last with the latest version available for FreeBSD

    All that I have under manage shell access is enable/disable...

    FTP is jailed, however SSH is not.

    I like to connect to FTP via SSH so that usernames and passwords are encrypted, I don't like making the people I share the server with login via plain text FTP, but I guess that they'll have to until the FreeBSD version supports Jail Shell.

  7. #7
    rnh
    rnh is offline
    Member
    Join Date
    Apr 2003
    Posts
    118

    Unhappy

    dangit. I switched to Cpanel because it was supposed to be more secure than Ensim because Ensim takes way too frigging long to update and then I had to go and choose FreeBSD over Linux because Linux had so many vulnerabilities last year and Cpanel ends up being several weeks behind on their FreeBSD version.

    Great

  8. #8
    Member SageBrian's Avatar
    Join Date
    Jun 2002
    Location
    NY/CT (US)
    Posts
    386

    Default

    But we're weeks AHEAD on mySQL and email issues.

    Hmmm, so Ensim doesn't update every other day? Maybe they try to make sure things are stable?

  9. #9
    Member This forum account has been confirmed by cPanel staff to represent a vendor. Radio_Head's Avatar
    Join Date
    Feb 2002
    Posts
    2,064
    Stop SPAM & VIRUS :: ASSP Deluxe for cPanel http://www.grscripts.com
    █ ASSP Deluxe is supported by Fritz Borgstedt,ASSP main developer.

  10. #10
    rnh
    rnh is offline
    Member
    Join Date
    Apr 2003
    Posts
    118

    Default

    Originally posted by SageBrian
    Hmmm, so Ensim doesn't update every other day? Maybe they try to make sure things are stable?
    yeah but I'd like a happy medium between "living life on the edge" (aka reporting bugs on a daily basis) and "I've been running my server for 6 months with widely known vulnerabilities installed with no option for patching them while I wait for some overpaid programmer to get done playing Everquest and spend 5 minutes renaming an RPM file from sendmail.x-x-x.3.whatever.rpm to sendmail.x-x-x.3.whatever.rpmEnsim8 so that it's compatible with the hacked Ensim RPMs on my system"

    It's so ridiculous... Ensim only has to take the work of some open source programmers and "apply their changes" whatever that happens to be, and we have to wait forever for their patches to come out before it's safe to upgrade.

    The problem with Cpanel is that they're spreading themselves too thin.

    Sure, Cpanel has a lot of features, but what good are features when NONE of them even work?

    I'd take unstable over insecure, but I'd like to be able to turn some of these features of Cpanel off as it's just too confusing and overwhelming for the end user. Nothing even works and they don't need all that crap.

  11. #11
    rnh
    rnh is offline
    Member
    Join Date
    Apr 2003
    Posts
    118

    Default

    again, what does this have to do with you?

Similar Threads & Tags
Similar threads

  1. Replies: 1
    Last Post: 02-08-2011, 03:34 PM
  2. sbox - chroot cPanel
    By dannato in forum Feature Requests for cPanel/WHM
    Replies: 0
    Last Post: 11-21-2009, 09:26 PM
  3. chroot vhost on cpanel
    By wahb in forum New User Questions
    Replies: 3
    Last Post: 12-01-2008, 02:53 PM
  4. Apache Chroot on cPanel ?!
    By #mOdY# in forum cPanel and WHM Discussions
    Replies: 16
    Last Post: 01-03-2007, 09:00 PM
  5. Cpanel in chroot Environment
    By mm1250 in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 11-27-2006, 10:51 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube