Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Page 19 of 19 FirstFirst ... 9 17 18 19
Results 271 to 279 of 279
  1. #271
    dfltech
    Guest

    Default

    Quote Originally Posted by Gilfil
    I had a box exploited...

    The user injected a ssh root code, changed my root password and replaced su by one of his own.

    I had to go inside the box through the exploit to restore the control, and re-install some RPMs of affected files.
    Do you have the root code? Can you paste it here? which RPMS were effected? Exactly how did he get the root access..

    Can you provide us with more information on this..

    Thanks.
    Adam.

  2. #272
    Member markfrompf's Avatar
    Join Date
    Mar 2006
    Location
    Los Angeles, CA
    Posts
    179

    Default

    <sarcasm>What? There are holes in cPanel?</sarcasm>

    I'm happy to see that you guys get these problems fixed so quickly. My server runs UPCP every night, so I'm safe.

    Keep up the good work and quick solutions!
    -----------------------------------------------------------
    | Mark A. Mutti: PhireFast Website Hosting
    | E: Mark.mutti@phirefast.com - P: (866) 350-4456 Ext. 100
    | 24/7 Support, 15 Minute Average Response Time
    | cPanel, Fantastico, Webmail & More!
    -----------------------------------------------------------

  3. #273
    PbG
    PbG is offline
    Registered User PbG's Avatar
    Join Date
    Mar 2003
    Posts
    235

    Default

    Please share your mod_security ruleset for blocking outgoing iframes?

    Quote Originally Posted by brianoz View Post
    And it would be useful data to know if you were using phpsuexec - were you?

    Is it possible to use mod_security to block outgoing iframes? That would make this vulnerability a heck of a lot harder to exploit and might provide another way to knobble the exploit temporarily.

  4. #274
    PbG
    PbG is offline
    Registered User PbG's Avatar
    Join Date
    Mar 2003
    Posts
    235

    Default

    ... too funny ROFL!

    Quote Originally Posted by myusername View Post
    A security audit by its very name should be conducted "online," to look for holes in a sytem in a state where it is accessable to the public. If it is offline and they are performing a security audit, its proabably because someone broke into their basement or garage and stole their computer they were hosting your site on, hense, they are now conducting an audit on their windows and doors.

  5. #275
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,093
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by PbG View Post
    Please share your mod_security ruleset for blocking outgoing iframes?
    I wouldn if I could but I can't because I don't. Have the ruleset, that is; I was asking whether someone had one. Would be a great tool to put in, even temporarily, when this sort of thing is around.

  6. #276
    PbG
    PbG is offline
    Registered User PbG's Avatar
    Join Date
    Mar 2003
    Posts
    235

    Default

    Host merit has some in his you can search for them. I wanted to compare yours with his/theirs.

    Quote Originally Posted by brianoz View Post
    I wouldn if I could but I can't because I don't. Have the ruleset, that is; I was asking whether someone had one. Would be a great tool to put in, even temporarily, when this sort of thing is around.

  7. #277
    Member markfrompf's Avatar
    Join Date
    Mar 2006
    Location
    Los Angeles, CA
    Posts
    179

    Default

    The exploit isn't really the problem. The problem is how the exploit is allover online news channels, etc. so everybody knows!

    I hate to say this, but maybe cPanel should just fix the exploits ASAP when they come out and just tell everyone "We've fixed a new exploit, please update cPanel" instead of telling the whole world about it and letting the hackers know how to recreate it!
    -----------------------------------------------------------
    | Mark A. Mutti: PhireFast Website Hosting
    | E: Mark.mutti@phirefast.com - P: (866) 350-4456 Ext. 100
    | 24/7 Support, 15 Minute Average Response Time
    | cPanel, Fantastico, Webmail & More!
    -----------------------------------------------------------

  8. #278
    Member myusername's Avatar
    Join Date
    Mar 2003
    Location
    chown -R us.us *yourbase*
    Posts
    699
    cPanel/Enkompass Access Level

    DataCenter Provider

    Default

    This is like 100 years old and they did fix it before the majority of the GP knew about it...
    GlowHost.com | Professional Managed Web Hosting Since 2002.
    >> Fully Managed Dedicated, Cloud VDS, Reseller & Semi-Dedicated
    >> Cloud Servers for Enterprise

  9. #279
    Member
    Join Date
    Jun 2004
    Location
    Jonesboro, AR
    Posts
    15

    Default

    Quote Originally Posted by markfrompf View Post
    The exploit isn't really the problem. The problem is how the exploit is allover online news channels, etc. so everybody knows!

    I hate to say this, but maybe cPanel should just fix the exploits ASAP when they come out and just tell everyone "We've fixed a new exploit, please update cPanel" instead of telling the whole world about it and letting the hackers know how to recreate it!
    Yeah, you're right. It's not like the exploit caused TONS of problems for the company that originally found it .. wait. It did. The exploit IS the problem.
    Michael Chase
    Clear-Data Internet Services - Inexpensive website, reseller, and game server hosting.

Similar Threads & Tags
Similar threads

  1. Possible Exploit?
    By CoryHawk in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-03-2007, 04:31 PM
  2. Major Major Problems
    By freemchr in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-11-2004, 04:21 AM
  3. SSH exploit
    By sparek-3 in forum cPanel and WHM Discussions
    Replies: 19
    Last Post: 10-06-2003, 08:37 AM
  4. ProFTP Exploit
    By Angel78 in forum cPanel and WHM Discussions
    Replies: 19
    Last Post: 09-28-2003, 09:54 PM
  5. proftpd exploit
    By JamesSmith in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-24-2003, 12:10 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube