Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member
    Join Date
    Sep 2005
    Posts
    5

    Lightbulb OpenSSL, Exim Version problems for PCI-Compliance

    cPanel is nightmare when it comes to PCI-Compliance I found out. I've been working on this for the last 2 weeks with no success.

    cPanel support recommended a change to the latest CURRENT build for the apparent compatible version, but no - it doesn't seem like it.

    After an update to the latest CURRENT cPanel, we fail OpenSSL version test. I installed OpenSSL latest manually but still fail.

    [root@sm1 ~]# rpm -qa | grep openssl
    openssl096b-0.9.6b-22.46
    openssl-devel-0.9.7a-43.17.el4_6.1
    openssl-0.9.7a-43.17.el4_6.1
    xmlsec1-openssl-1.2.6-3
    [root@sm1 ~]#

    [root@sm1 ~]# openssl version
    OpenSSL 0.9.8i 15 Sep 2008
    [root@sm1 ~]#

    Also a NEW exim problem now:

    The remote host is running a version of the Exim MTA which is vulnerable to several remote buffer overflows. Specifically, if either 'headers_check_syntax' or 'sender_verify = true' is in the exim.conf file, then a remote attacker may be able to execute a classic stack- based overflow and gain inappropriate access to the machine. *** If you are running checks with safe_checks enabled, this may be a false positive as only banners were used to assess the risk! *** It is known that Exim 3.35 and 4.32 are vulnerable. Solution: Upgrade to Exim latest version Risk Factor: High [More] [Hide]

    Our exim is the latest version...

    Anybody had these problems with their cPanel servers? How helpful were the cPanel support team to you in getting these resolved?

  2. #2
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,788
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    The OpenSSL matter is more than likely a false positive. You will find some very good threads on the forum about such matters. Search for PCI OpenSSL. And likewise with Exim.

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge lostmind's Avatar
    Join Date
    May 2006
    Location
    Vancouver, BC
    Posts
    9
    cPanel/Enkompass Access Level

    DataCenter Provider

    Default

    May I suggest an email to cpanel support?

    They have been extremely helpful when it comes to this.

Similar Threads & Tags
Similar threads

  1. PCI Compliance - Exim
    By tps in forum Security
    Replies: 3
    Last Post: 01-08-2010, 10:55 PM
  2. PCI Compliance - Exim
    By tps in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 12-23-2009, 12:14 PM
  3. POP3/EXIM plain text password (PCI Compliance)
    By p1mp in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 04-06-2009, 09:08 PM
  4. Security Metrics PCI compliance - Exim fails test.
    By jols in forum E-mail Discussions
    Replies: 6
    Last Post: 12-11-2008, 11:55 PM
  5. OpenSSL banner / PCI compliance
    By ndial in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 06-17-2005, 11:30 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube