Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 12 of 12
  1. #1
    Member
    Join Date
    Apr 2003
    Location
    Norway
    Posts
    26

    Default Security of accounts on cpanel servers.

    If a cpanel server is running PHP as a module in Apache I will be able to read/edit other peoples files if (assuming that apache runs with user nobody):
    I upload a CGI/PHP script so that it is owned by user nobody. PHP will then be restricted by safe_mode or open_basedir, but CGI will not be restricted by anything. If another account on the same server has files owned by user nobody, I will have full access to these using CGI (and might have access with PHP depending on safe_mode/open_basedir).

    Are my assumtions correct? I'm writing a master thesis so I would really appreciate if anyone could reply

  2. #2
    Member
    Join Date
    Jan 2004
    Location
    Roswell, GA
    Posts
    363

    Default

    Off topic, but I am the Number1Host

    Number1Host.net
    Shared, Reseller, and Dedicated Hosting
    Server Setup, Management, and Security
    The Web's Number 1 Host - Number1Host.net

  3. #3
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    Quote Originally Posted by cooldude7273
    Off topic, but I am the Number1Host

    Why did you not register it?
    Regards,
    David
    Forum Moderator

  4. #4
    Member
    Join Date
    Jan 2004
    Location
    Roswell, GA
    Posts
    363

    Default

    Quote Originally Posted by dgbaker
    Why did you not register it?
    I don't think I was Number1Host when I signed up here, not a big deal to me though.
    Number1Host.net
    Shared, Reseller, and Dedicated Hosting
    Server Setup, Management, and Security
    The Web's Number 1 Host - Number1Host.net

  5. #5
    Member
    Join Date
    Apr 2003
    Location
    Norway
    Posts
    26

    Default

    Well I registered in Apr 2003 with that nick (and domain) so I think I was before you Though we have changed name since then.

    But on topic, someone here able to answer?

  6. #6
    Member
    Join Date
    May 2006
    Posts
    11

    Talking

    Quote Originally Posted by numberonehost
    If a cpanel server is running PHP as a module in Apache I will be able to read/edit other peoples files if (assuming that apache runs with user nobody):
    I upload a CGI/PHP script so that it is owned by user nobody. PHP will then be restricted by safe_mode or open_basedir, but CGI will not be restricted by anything. If another account on the same server has files owned by user nobody, I will have full access to these using CGI (and might have access with PHP depending on safe_mode/open_basedir).

    Are my assumtions correct? I'm writing a master thesis so I would really appreciate if anyone could reply
    I think you're correct. Of course this is basing upon simular ways I do this. Although not too sure about every single detail with 'safe_mode/open_basedir' . Since I prefer to let my clients edit their own files and their sites, I find myself just leaving things alone.

    Quote Originally Posted by cooldude7273
    Off topic, but I am the Number1Host

    Lol, I thought I was the World's Number 1 hosting Company. Well, I'm at least one of the best in support.... oh well, btw nice site you have there numberonehost!
    Get your domain name today! .COMs from just $7.95/yr! Sign up today!-- http://www.widenationhost.com/

    Sales Dept: sales@widenationhost.com
    Support Forum: http://widenationhost.com/forums/index.php

    All domain transfers and renews are just $6.95 for a limited time. Regular price domains for $3.99 with purchase of non-domain product such as our hosting plans which start at $4.95/mo.

  7. #7
    Member
    Join Date
    Jan 2004
    Location
    Roswell, GA
    Posts
    363

    Default

    Nonono, you see, I am the Number1Host

    See?
    Number1Host.net
    Shared, Reseller, and Dedicated Hosting
    Server Setup, Management, and Security
    The Web's Number 1 Host - Number1Host.net

  8. #8
    Member
    Join Date
    Apr 2003
    Location
    Norway
    Posts
    26

    Default

    btw nice site you have there numberonehost!
    Thanks BTW I got forbidden on your pages?

    So this is basically possible:
    If a file "file" in
    /home/userA/public_html/file
    is owned by nobody and a directory "dir" in
    /home/userB/public_html/dir
    is owned by nobody (and all the subdirs and files), then userA would have access to everything within directory dir of userB?

  9. #9
    Member
    Join Date
    Jan 2004
    Location
    Roswell, GA
    Posts
    363

    Default

    As long as you have open_basedir enabled, you won't have a problem.
    Number1Host.net
    Shared, Reseller, and Dedicated Hosting
    Server Setup, Management, and Security
    The Web's Number 1 Host - Number1Host.net

  10. #10
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    That's not true. If you have open_basedir enabled it makes it a tiny bit more tricky, but it's trivial to bypass.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  11. #11
    Member
    Join Date
    Jan 2004
    Location
    Roswell, GA
    Posts
    363

    Default

    ^^ What he said. Chirpy > cooldude
    Number1Host.net
    Shared, Reseller, and Dedicated Hosting
    Server Setup, Management, and Security
    The Web's Number 1 Host - Number1Host.net

  12. #12
    Member
    Join Date
    Apr 2003
    Location
    Norway
    Posts
    26

    Default

    So to sum up my assumtion is correct?

    Thank you all for your answers so far

Similar Threads & Tags
Similar threads

  1. Use cpanel servers as nameserver for other accounts?
    By kjg in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 06-22-2009, 11:56 AM
  2. Replies: 21
    Last Post: 05-08-2003, 03:31 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube