Community Forums
Connect with us on LinkedIn
Closed Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 26
  1. #1
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default proftpd security vulerability??? Where can I find more info?

    proftpd security vulerability??? Where can I find more info?

    was this on Bug Traq, I dont remember seeing anything on it.

    Security At this time, it is recommended that all customers using proftpd Switch to pure-ftpd as soon as possible to eliminate a potential security hole. Please note that all released versions of proftpd are belived to be affected and the exact problem is not yet known. Customers who experience the problems switching are welcomed to bypass the normal support procedure and submit a ticket directly at http://support.cpanel.net

  2. #2
    Registered User
    Join Date
    Apr 2005
    Posts
    1

    Default

    I also can't find anything on this other than at cPanel. We have this on some of our other non cPanel machines and it's working OK, and I really don't want to switch to Pure due to its poor scalability. Can we get input from someone at cPanel as to a specific Secunia advisory or a specific bug that's reported in Bugzilla?

  3. #3
    Registered User
    Join Date
    Mar 2004
    Posts
    3

    Default switch to pureFtp - FAILED

    I have attempted to switch from proFtp to pureFtp but it fails.

    WHM 9.9.9 cPanel 9.9.9-R14
    SuSE 8.2 i686 - WHM X v3.1.0

    thoughts?

  4. #4
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,597

    Default

    Quote Originally Posted by BianchiDude
    proftpd security vulerability??? Where can I find more info?

    was this on Bug Traq, I dont remember seeing anything on it.

    Security At this time, it is recommended that all customers using proftpd Switch to pure-ftpd as soon as possible to eliminate a potential security hole. Please note that all released versions of proftpd are belived to be affected and the exact problem is not yet known. Customers who experience the problems switching are welcomed to bypass the normal support procedure and submit a ticket directly at http://support.cpanel.net
    This has yet to be offically confirmed. However I was personally able to get root with proftpd 1.3.0rc1, and I've been told others have had success doing so with 1.2.0.

  5. #5
    Member manokiss's Avatar
    Join Date
    Mar 2002
    Posts
    536

    Default

    ok, but what about all the bugs pure-ftpd have? like the quota setup and those things? there will be any fix today?

  6. #6
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,597

    Default

    Quote Originally Posted by manokiss
    ok, but what about all the bugs pure-ftpd have? like the quota setup and those things? there will be any fix today?
    The only known problem with pure-ftpd is editting the quota..which may already be fixed in edge (waiting for qa verification)

  7. #7
    Registered User
    Join Date
    Jul 2005
    Posts
    3

    Default

    Just out of curiousity: Is this also an issue with a grsec patched kernel?

  8. #8
    Member manokiss's Avatar
    Join Date
    Mar 2002
    Posts
    536

    Default

    that will be great Nick, thank you!

  9. #9
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default

    Quote Originally Posted by cpanelnick
    This has yet to be offically confirmed. However I was personally able to get root with proftpd 1.3.0rc1, and I've been told others have had success doing so with 1.2.0.
    How did you get root?

  10. #10
    cPanelBilly
    Guest

    Default

    Quote Originally Posted by BianchiDude
    How did you get root?
    That will not be released publicly

  11. #11
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default

    Quote Originally Posted by cPanelBilly
    That will not be released publicly
    Kindly tell me in a Private Message.

  12. #12
    cPanelBilly
    Guest

    Default

    Quote Originally Posted by BianchiDude
    Kindly tell me in a Private Message.
    This also will not be done.

  13. #13
    Registered User
    Join Date
    Jul 2005
    Posts
    3

    Default

    Well, anything that is hindering you from "releasing publicly" if this is also an issue with grsec? :-)

  14. #14
    Registered User
    Join Date
    Jul 2005
    Posts
    3

    Default

    Well, apparently there is. Too bad :-(.

  15. #15
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,597

    Default

    Quote Originally Posted by fubfub
    Well, anything that is hindering you from "releasing publicly" if this is also an issue with grsec? :-)

    We were not able to confirm it on more then one machine so far. At this point, its just an advisory. We feel its better to be proactive instead of reactive in the event it does turn out to be a major problem. Given that pure-ftpd has a better security history then proftpd, we feel this is the wisest course at this time.

Closed Thread
Page 1 of 2 1 2 LastLast
Similar Threads & Tags
Similar threads

  1. Were Do I Find my dattabase Info??
    By walkingjukebox in forum Database Discussions
    Replies: 4
    Last Post: 01-20-2009, 03:36 PM
  2. how do i find out my SMTP info?
    By Lawrence89 in forum E-mail Discussions
    Replies: 1
    Last Post: 02-15-2008, 02:40 PM
  3. How do I find total server bandwidth info ?
    By 4u123 in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 01-09-2007, 07:54 AM
  4. Proftpd info (ftp.DOMAIN.com)
    By Angel78 in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-07-2004, 06:05 PM
  5. Replies: 3
    Last Post: 08-06-2004, 03:32 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube