Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 12 of 12
  1. #1
    Member
    Join Date
    Mar 2003
    Posts
    222
    cPanel/Enkompass Access Level

    Root Administrator

    Default Securing Cpanel Server

    Hi,

    By using scdipts like PHP Shell, a user can view other users files, view the content of scripts, data files, etc...

    So other users files are not secure. I found Enism advertise it will secure users data.

    I have found some cpanel servers do this with out turning ON php safe mode.

    How to solve this ?

    Regards,

    Yujin

    cPanel.net Support Ticket Number:

  2. #2
    Member
    Join Date
    Feb 2003
    Posts
    62

    Default

    use open_basedir and disable function, but this is only php. Any user with CGI access still can view other user files.

    cPanel.net Support Ticket Number:

  3. #3
    Member
    Join Date
    Mar 2003
    Posts
    222
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    How to use open_basedir and disable function ?

    Can you explain ?

    Is it possible to chmod /home folder to some thing different ?

    Hope running suexe will solve the cgi problem.

    cPanel.net Support Ticket Number:

  4. #4
    Member cass's Avatar
    Join Date
    Jul 2002
    Location
    Argentina/USA/Mexico
    Posts
    354

    Default

    If you have your WHM updated ... (to version 7.0.x)
    you can use :

    tweak security link in WHM.

    Regards.

    cPanel.net Support Ticket Number:
    Carlos Ariel Sepúlveda
    CAS company :: 1997-2011, 14 Years! :: Dedicated Attitude
    http://www.cascompany.com :: Providing CPANEL/WHM Servers since 2002 !

  5. #5
    Member
    Join Date
    Mar 2003
    Posts
    222
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    I was using Stable Tree.

    WHM 6.4.2 Cpanel 6.4.2-S75 RedHat 7.3

    Now updating to Release Tree. Hope this will update WHM to v7.

    cPanel.net Support Ticket Number:

  6. #6
    Member cass's Avatar
    Join Date
    Jul 2002
    Location
    Argentina/USA/Mexico
    Posts
    354

    Default

    Hum... well... if you look at layer2.cpanel.net you'll see that the last non EDGE non BETA release is :
    Cpanel-6.4.2-STABLE_85-FreeBSD-i386-libc (Tue Jun 10 08:42:46 2003)

    But you need 7.0.5 or Up. for this feature.
    or wait to July when version 7 will be stable.

    Regards.

    cPanel.net Support Ticket Number:
    Carlos Ariel Sepúlveda
    CAS company :: 1997-2011, 14 Years! :: Dedicated Attitude
    http://www.cascompany.com :: Providing CPANEL/WHM Servers since 2002 !

  7. #7
    Member
    Join Date
    Mar 2003
    Posts
    222
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Hi,

    I tryed updating Cpanel to RELEASE tree.

    It get updated to

    WHM 6.4.2 Cpanel 6.4.2-R79

    WHM 7 is in EDGE tree ?

    Regards,

    Yujin

    cPanel.net Support Ticket Number:

  8. #8
    Member cass's Avatar
    Join Date
    Jul 2002
    Location
    Argentina/USA/Mexico
    Posts
    354

    Default

    Yes, CPANEL 7 is on EDGE.

    cPanel.net Support Ticket Number:
    Carlos Ariel Sepúlveda
    CAS company :: 1997-2011, 14 Years! :: Dedicated Attitude
    http://www.cascompany.com :: Providing CPANEL/WHM Servers since 2002 !

  9. #9
    Member
    Join Date
    Mar 2003
    Posts
    222
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Thanks for the reply.

    I will wait for v7 available in Stable Tree.

    cPanel.net Support Ticket Number:

  10. #10
    Member
    Join Date
    Mar 2003
    Posts
    35

    Default

    Originally posted by cass
    If you have your WHM updated ... (to version 7.0.x)
    you can use :

    tweak security link in WHM.

    Regards.

    cPanel.net Support Ticket Number:
    Where is tweak security link located in WHM?

    cPanel.net Support Ticket Number:

  11. #11
    Member
    Join Date
    Feb 2003
    Posts
    62

    Default

    I'm also interested, what is exactly that tweak doing?

    cPanel.net Support Ticket Number:

  12. #12
    Member cass's Avatar
    Join Date
    Jul 2002
    Location
    Argentina/USA/Mexico
    Posts
    354

    Default

    It modifies the httpd.conf virtual hosts by default
    and adds security for PHP (lock includes on user dir & tmp only, etc.)

    Regards.

    cPanel.net Support Ticket Number:
    Carlos Ariel Sepúlveda
    CAS company :: 1997-2011, 14 Years! :: Dedicated Attitude
    http://www.cascompany.com :: Providing CPANEL/WHM Servers since 2002 !

Similar Threads & Tags
Similar threads

  1. Securing a new cPanel server, suExec, suPHP etc
    By Dragooon in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-19-2011, 07:53 AM
  2. Replies: 1
    Last Post: 11-20-2009, 01:41 PM
  3. Guide to securing a server?
    By hexstar in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 09-04-2007, 11:10 PM
  4. Securing server with SSL
    By Logger in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 03-26-2003, 02:02 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube