Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Jul 2005
    Posts
    609

    Default Security issue?

    Is this a security issue?

    I noticed when restoring an account the files are owned by root until the end of the restore process, and are also owned by the group root, when all the files are chowned back to the regular username.

    For a large account it can often take 30min - 1 hour or more to restore.

    Does this pose a security risk?

  2. #2
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    Quote Originally Posted by BianchiDude View Post
    Is this a security issue?

    I noticed when restoring an account the files are owned by root until the end of the restore process, and are also owned by the group root, when all the files are chowned back to the regular username.

    For a large account it can often take 30min - 1 hour or more to restore.

    Does this pose a security risk?
    i would think that would be a security advantage NOT a risk?
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  3. #3
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,788
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    As long as none are setuid, there should be little to no problem with this. Being owned by root, the user will have little control over the files, especially when accessed via the cPanel interface as we perform a number of checks when performing actions as the user.

    Since the restore process is not executing anything in the backup, any attack vector would be vanishingly small to non-existent.

Similar Threads & Tags
Similar threads

  1. Is this a security issue?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 07-18-2006, 03:04 PM
  2. Security issue
    By prof in forum Security
    Replies: 3
    Last Post: 02-21-2006, 11:31 AM
  3. Possible security issue
    By GordonH in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-27-2004, 04:38 AM
  4. Security Issue..Can some one help
    By wipl in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 10-14-2003, 09:32 AM
  5. security issue
    By NNNils in forum cPanel and WHM Discussions
    Replies: 16
    Last Post: 04-28-2003, 02:55 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube