Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Page 12 of 19 FirstFirst ... 2 10 11 12 13 14 ... LastLast
Results 166 to 180 of 279
  1. #166
    Member
    Join Date
    Jul 2004
    Posts
    203

    Default

    An issue yes. A major issue no.

    A security issue must be dealt with as a higher priority. This issue isn;t really that much of an issue as most users just set-up the DB and user perms then move on to a web based SQL injection process, therefore phpMyAdmin would only be a tool to debug an SQL site.

    All in all, its an issue that does require some attention
    Regards,
    RAIS


    { RAIS Hosting }~{ Superior Hosting Solutions - Personal, Business, Reseller Solutions. Great value }
    { RAIS Domains }~{ Low cost Domain Name registration services }

  2. #167
    Member
    Join Date
    Dec 2003
    Location
    PA
    Posts
    108
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    our issue is that cpanel isnt recognizing the databases at all.
    we cant create new ones
    and we cant see exsisting ones

    If you try to hit phpmyadmin you get a wrong username and pass error

  3. #168
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,514

    Default Updated Patcher/Checker (this will probably be the final one for the security adviso

    Updated Patcher:
    http://layer1.cpanel.net/installer/sec092406.pl

    Updated Checker:
    http://layer1.cpanel.net/installer/c...cker_092406.pl

    The auto patcher in the installer has been updated

    Summary:
    * The patch is now pure perl and doesn't rely on the 'patch' utility (this was causing older version of cPanel to not be patched).
    * Solves Problems with mysql interaction on 64-bit systems.
    * Solves Problems with creating databases with non latin charsets.
    * More robust security checks (the last patch could still allow the exploit to work if it was modified if you were running RELEASE/STABLE [the CURRENT,EDGE,NIGHTLY have a patch in the wrapper that stops this problem dead instead of patching around it] )

    The offical security advisory should be ready late tonight/tomorrow morning.

  4. #169
    Member
    Join Date
    Jul 2004
    Posts
    203

    Default

    Quote Originally Posted by merlinpa1969
    our issue is that cpanel isnt recognizing the databases at all.
    we cant create new ones
    and we cant see exsisting ones

    If you try to hit phpmyadmin you get a wrong username and pass error
    Search the cPanel forums, I had that error before.

    I **Think** I simply reset the root MySQL password, I can't remember for sure though.
    Regards,
    RAIS


    { RAIS Hosting }~{ Superior Hosting Solutions - Personal, Business, Reseller Solutions. Great value }
    { RAIS Domains }~{ Low cost Domain Name registration services }

  5. #170
    Member
    Join Date
    Jun 2002
    Posts
    49

    Default What is going on here?

    This mess just keeps getting worse.

    I just updated a cPanel server that the script then said was secure:

    # perl sec092306.pl
    cPanel Security Patch (sec092306) v2
    Patching Mysql (1)
    Patching Mysql (2)
    Patching Mysql (3)
    Patching Mysql (4)
    Patching Mysql (1)
    Patching Mysql (2)
    Patching Mysql (3)
    Patching Mysql (4)
    Patch Complete
    Checking for safety...

    safe

    Done
    Ran it again a few minutes later

    # perl sec092306.pl
    cPanel Security Patch (sec092306) v2
    Patching Mysql (1)
    Patching Mysql (2)
    Patching Mysql (3)
    Patching Mysql (4)
    Patching Mysql (1)
    Patching Mysql (2)
    Patching Mysql (3)
    Patching Mysql (4)
    Patch Complete
    Checking for safety...

    not safe

    Done
    So how does a server that was 'secure' now becoming insecure? Running /scripts/upcp again didn't fix it either.

    I have no clue what is going on anymore.

    Hal

  6. #171
    Member
    Join Date
    Jan 2004
    Posts
    123

    Default

    Am I allowed to ask why we are patching rather than just replacing the file and incrementing the version number so that people have a dead cert way of easily identifying a vulnerable version?

  7. #172
    Member
    Join Date
    May 2005
    Posts
    235

    Default

    Your link for the checker is broken.

  8. #173
    Member rs-freddo's Avatar
    Join Date
    May 2003
    Location
    Australia
    Posts
    819
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by rs-freddo
    You don't need to do --force just /scripts/upcp

    The reason it didn't work the first time is that cpanel put out two patches. The first one only did half the job, which is why you had to run /scripts/upcp later in the day. If you were one of the people who patched early - you need to test your boxes, chances are you need to run /scripts/upcp again.
    And cPanel have issued a third patch, so if you have patched previously you need to patch again...
    Michael

  9. #174
    Member
    Join Date
    Jun 2002
    Posts
    49

    Default

    EDIT: Never mind me. Being stupid.

    Hal
    Last edited by hbouma; 09-24-2006 at 06:33 PM.

  10. #175
    Member
    Join Date
    Mar 2005
    Posts
    5

    Default

    From the patch checker tool I am getting:

    Code:
    Checking /usr/local/cpanel/bin/mysqladmin...safe..Done
    Checking /usr/local/cpanel/bin/hooksadmin...not installed (ok) Done
    Your system has been
    patched!
    Is this ok?

  11. #176
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,514

    Default

    Quote Originally Posted by zigzam
    Your link for the checker is broken.
    Probably still propgating to all the update server .. try again in 30 sec.

  12. #177
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,514

    Default

    Quote Originally Posted by cinusik
    cpanelnick, what about mysql issue? any progress? Thanks in advance for your reply.
    http://bugzilla.cpanel.net/show_bug.cgi?id=4611
    Confirmed on our 20 servers and few people here.
    Its being worked on right now (#2 priority though)

  13. #178
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,514

    Default

    Quote Originally Posted by bogdan2003
    From the patch checker tool I am getting:

    Code:
    Checking /usr/local/cpanel/bin/mysqladmin...safe..Done
    Checking /usr/local/cpanel/bin/hooksadmin...not installed (ok) Done
    Your system has been
    patched!
    Is this ok?

    Yes, by all means.

  14. #179
    Member
    Join Date
    Jun 2004
    Location
    Jonesboro, AR
    Posts
    15

    Default

    I've had no problems getting the patch applied (after the 3 updates in an hour yesterday); however, I (like a lot of the other people here) am having issues with PHPMyAdmin. I understand that this is less of a priority than a priviledge escalation but it's still a huge huge problem.
    Michael Chase
    Clear-Data Internet Services - Inexpensive website, reseller, and game server hosting.

  15. #180
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,514

    Default

    Quote Originally Posted by rs-freddo
    And cPanel have issued a third patch, so if you have patched previously you need to patch again...
    If you are running the latest CURRENT/EDGE/NIGHTLY there is no need to patch unless you are having problems with mysql.


    Hopefully the last. We will put out as many revisions as needed to make sure it works for everyone. (we targeted 48 hours to be 100% [read above].. looks like we are still on target for that)

Similar Threads & Tags
Similar threads

  1. Possible Exploit?
    By CoryHawk in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-03-2007, 04:31 PM
  2. Major Major Problems
    By freemchr in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-11-2004, 04:21 AM
  3. SSH exploit
    By sparek-3 in forum cPanel and WHM Discussions
    Replies: 19
    Last Post: 10-06-2003, 08:37 AM
  4. ProFTP Exploit
    By Angel78 in forum cPanel and WHM Discussions
    Replies: 19
    Last Post: 09-28-2003, 09:54 PM
  5. proftpd exploit
    By JamesSmith in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-24-2003, 12:10 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube