Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 17
  1. #1
    Member
    Join Date
    Sep 2002
    Posts
    580

    Default security issue

    Help!

    I got this e-mail from someone (it's in dutch):

    -----------------------
    Lo admin,

    [my ip-address was here] -> /etc/evilfile
    got r00t? :]
    hehe, dat ging zeer makkelijk met ptrace.. Patch je kernel
    misschien ook voorkomen dat "gebruikers" een shell kunnen spawnen via httpd?
    en uh.. zelfs dingen als ls/cd 750 zetten en shellgebruikers toevoegen aan een groep
    Read The Fine security howto/checklist

    /JaD
    -------------------------

    He tells the following bad issues:

    - he managed to get in /etc and place a file called evilfile (using ptrace???)
    - he recommends patching kernel
    - he says users can "spawn" a shell through httpd
    - he tells ls/cd are 750, which is insecure according to him
    - shell users are added to a group

    He recommends reading The Fine security howto/checklist



    Please help with this.

  2. #2
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Hi, you need to upgrade your kernel, you can search on 'kernel' in this forum for more information.

    Be careful doing this yourself though, because if something goes wrong you might not be able to get the server up again.

    You should probably contact your NOC and ask them to do it for you.

  3. #3
    Member
    Join Date
    Sep 2002
    Posts
    580

    Default

    Hm... didn't got kernelcheck messages...

  4. #4
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Originally posted by NNNils
    Hm... didn't got kernelcheck messages...
    You shouldn't rely on CPanel for these issues

    Log on to your server and type : uname -a to see your kernel version.

  5. #5
    Member
    Join Date
    Sep 2002
    Posts
    580

    Default

    It is 2.4.18-26.7.x

    What version(s) is okay?

    Are all the issues this person tells me, solved in an other kernel or are their also issues result of the way cpanel works?

  6. #6
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Originally posted by NNNils
    It is 2.4.18-26.7.x

    What version(s) is okay?


    The latest version, 2.4.18-27.7.x I believe.

    Are all the issues this person tells me, solved in an other kernel or are their also issues result of the way cpanel works?
    The permissions you have set are the default permissions as far as i know.

    Giving SSH access to users is something you have to be careful with.
    Last edited by jamesbond; 04-12-2003 at 05:53 AM.

  7. #7
    Member
    Join Date
    Sep 2002
    Posts
    580

    Default

    Originally posted by jamesbond
    The latest version, 2.4.18-27.7.x I believe.

    The permissions and adding to the wheel group is the default setup as far as i know.

    Shouldn't something be done about that too then?

  8. #8
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    You can use the jailshell option, you can enable that to 'jail' the users in their own dir.

    But even with jailshell you should still be careful who you give shell access to.

  9. #9
    Member
    Join Date
    Sep 2002
    Posts
    580

    Default

    On the whole server there is just 1 shell user...

    I have now given him jailed shell.

  10. #10
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    That's good, by the way I was wrong with what I said that users are added to the wheel group by default, at least this doesn't happen on my server.

    Maybe you accidently added him to the wheel group?
    In WHM there is an option 'Add/Remove Users from the Wheel'

  11. #11
    Member
    Join Date
    Sep 2002
    Posts
    580

    Default

    Nope never used that option.

    How can I see if a user is added to the wheel group?

    BTW what is a wheel group :-S ?

  12. #12
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Just log on to WHM and click on ' 'Add/Remove Users from the Wheel' , there you should see who is in the wheel group.

    users in the wheel group are allowed to su to root (if they know the root pwd ofcourse)

    users who are not in the wheel group can't su to root even if they know the root pwd.

  13. #13
    Member
    Join Date
    Sep 2002
    Posts
    580

    Default

    Only root is in wheel group

  14. #14
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Well then I don't know what group he is talking about.

    To see a list of the groups on your server you can do this in SSH : cat /etc/group

  15. #15
    Member
    Join Date
    Sep 2001
    Posts
    87

    Default

    Will upgrading to the newest kernel via up2date mess Cpanel up in any way?

Similar Threads & Tags
Similar threads

  1. Security issue?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 04-21-2008, 08:12 AM
  2. Is this a security issue?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 07-18-2006, 04:04 PM
  3. Security issue
    By prof in forum Security
    Replies: 3
    Last Post: 02-21-2006, 12:31 PM
  4. Possible security issue
    By GordonH in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-27-2004, 05:38 AM
  5. Security Issue..Can some one help
    By wipl in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 10-14-2003, 10:32 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube