Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 16
  1. #1
    Member
    Join Date
    Jun 2003
    Posts
    20

    Angry A possible BUG that is very serious!! ROOT ACCESS

    Ok one of my customers reported that he was able to type "su" in his jailshell and it gave him root without even asking for a password. I didn't believe it until I logged in using a regular account and typed su... before I could even realize I had root access on important folders on the system like /var /tmp /bin /usr.

    This is of course a very serious BUG affecting my Cpanel WHM 9.4.0 cPanel 9.4.1-E73 on FreeBSD 5.2.1-RELEASE-p8, I'm not sure if it's an isolated problem or a general one so I would appreciate if some of you guys could test it on your own servers.


    Jean-Pierre Abboud

  2. #2
    Member casey's Avatar
    Join Date
    Jan 2003
    Location
    If there is trouble, it will find me
    Posts
    2,336

    Default

    /bin/su permission denied

    is the response I get.

  3. #3
    Member
    Join Date
    Jun 2003
    Posts
    20

    Default

    Ok what version of Cpanel/Operating System ?

    Quote Originally Posted by casey
    /bin/su permission denied

    is the response I get.

  4. #4
    Member
    Join Date
    Jul 2004
    Posts
    7

    Default

    /bin/su permission denied
    RHE
    WHM 9.4.0 cPanel 9.4.1-R64

  5. #5
    Member
    Join Date
    Feb 2004
    Location
    Sydney, Australia
    Posts
    57

    Default

    Our /bin/su has permissions to execute and read removed from non-wheel and non-root users anyway. When moved back, tested with users, with and without jailshell, users cant escalate priveleges to uid=0. Running latest cPanel RELEASE.
    God is in his own heaven and all is right with the world.
    http://magi.net.au - Have some fun!

  6. #6
    Member
    Join Date
    Jun 2003
    Posts
    20

    Default

    Quote Originally Posted by K_aneda
    Our /bin/su has permissions to execute and read removed from non-wheel and non-root users anyway. When moved back, tested with users, with and without jailshell, users cant escalate priveleges to uid=0. Running latest cPanel RELEASE.
    I'm curious to see if any of those tests were done on a FreeBSD server, the FreeBSD jailshell has been really unstable/buggy so it wouldn't surprise me if it was affecting only FreeBSD servers.

  7. #7
    Member
    Join Date
    Feb 2004
    Location
    Sydney, Australia
    Posts
    57

    Default

    Oops forgot to quote OS, Redhat Enterprise 3.0ES... yes it would, maybe we should ask the techs in the IRC channel, no?
    God is in his own heaven and all is right with the world.
    http://magi.net.au - Have some fun!

  8. #8
    Member casey's Avatar
    Join Date
    Jan 2003
    Location
    If there is trouble, it will find me
    Posts
    2,336

    Default

    Quote Originally Posted by jpabboud
    Ok what version of Cpanel/Operating System ?
    CentOS, RH9 / Current build of cPanel

  9. #9
    Member
    Join Date
    Jun 2003
    Posts
    20

    Default

    Quote Originally Posted by K_aneda
    Oops forgot to quote OS, Redhat Enterprise 3.0ES... yes it would, maybe we should ask the techs in the IRC channel, no?
    I immediately opened a ticket with Cpanel... What's the IRC server, channel (sorry never visited before).

  10. #10
    Member netwrkr's Avatar
    Join Date
    Apr 2003
    Posts
    203

    Default

    Quote Originally Posted by jpabboud
    Ok one of my customers reported that he was able to type "su" in his jailshell and it gave him root without even asking for a password. I didn't believe it until I logged in using a regular account and typed su... before I could even realize I had root access on important folders on the system like /var /tmp /bin /usr.

    This is of course a very serious BUG affecting my Cpanel WHM 9.4.0 cPanel 9.4.1-E73 on FreeBSD 5.2.1-RELEASE-p8, I'm not sure if it's an isolated problem or a general one so I would appreciate if some of you guys could test it on your own servers.


    Jean-Pierre Abboud
    For future reference please send security related issues to security@cpanel.net. This is a public forum which everyone (cpanel owners and hackers) can view.

    Thanks.
    Thomas Petersen
    Myriad Network
    http://www.myriadnetwork.com

  11. #11
    cPanelBilly
    Guest

    Default

    I just tested this on a
    WHM 9.7.2 cPanel 9.7.2-E16
    FreeBSD 5.1-RELEASE i386 - WHM X v3.1.0
    server and was not able to replicate the issue. Can you please put in a ticket and either PM me the ticket # or post it here so I can have a look into it.

  12. #12
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,597

    Default

    I am also unable to verify this, tested 1 linux, 1 amd64 freebsd box and 3 i386 freebsd boxes.

  13. #13
    Member
    Join Date
    May 2003
    Posts
    239

    Default

    I have tested it on 4.10 and did not work. With Jailshell you can't get SU at all. with regular shell obviously need to enter a password.

    Must be something with your machine, bro.

  14. #14
    Member
    Join Date
    Oct 2003
    Location
    Nirvana
    Posts
    184

    Default

    You may have been rooted and your su binary may have been modified. I recommend getting your box checked out.
    http://www.lifelesspeople.com/ The revolution has begun! Pay by Post™ Webhosting is here!

  15. #15
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    May 2002
    Posts
    122

    Default

    I have also been able to verify this. It appears that only a portion of the files are visible, possbily only those in virtfs, but su does execute and returns "root" when executing whoami command.

Similar Threads & Tags
Similar threads

  1. Access root to a server in cluster -> access to dns ?
    By altomarketing2 in forum Security
    Replies: 1
    Last Post: 03-15-2011, 11:09 AM
  2. Replies: 8
    Last Post: 06-24-2009, 06:20 PM
  3. bug report : root access with a reseller account.
    By php-empire in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 11-10-2008, 04:30 AM
  4. WHM Bug: Root Access Denied
    By andren in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 08-22-2008, 04:55 AM
  5. cpanel bug / Get root access with root password
    By majidnt in forum cPanel and WHM Discussions
    Replies: 19
    Last Post: 08-24-2005, 11:12 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube