This is exactly what i was afraid of and i addressed the issue some weeks back. SSH and the users ability to stray out of their virtual domain webspace. Now unless i am crazy or something this user also modified httpd.conf to suit their own likeing. I am still investigating to find out how the following was added to the users virtual domain container:
&VirtualHost 64.246.38.122&
ServerAlias www.reseller-watercool.com reseller-watercool.com
ServerAdmin webmaster@reseller-watercool.com
DocumentRoot /home/coffero/public_html
BytesLog domlogs/reseller-watercool.com-bytes_log
User coffero
Group coffero
ServerName www.reseller-watercool.com
CustomLog domlogs/reseller-watercool.com combined
Options -ExecCGI -Includes &&&&--------------------------- LOOK!@
&/VirtualHost&
I sure didnt add it so how did it get there.
We had a situation here yesterday where a reseller setup an account called cristy.com. Yes they were able to deliagate SSH capabilities to their users and all users have been warned that if our server is jeapadized because of one of their customers they will be responsible.
I guess the warning didnt sink in somebodies head and while online yesterday i noticed all these servers connecting to port 6667. Checking the users virtual domain revealed nothing, just frontpage directories with zero content.
It was time to look for hidden directories and upon doing so, we found the following hidden directory, created by cristy after leaving her own virtual domain space: /tmp/.,.
/tmp/.,. contains the following:
drwxr-xr-x 3 cristy cristy 4096 Jan 4 06:21 ./
drwxrwxrwt 3 root root 4096 Jan 5 14:02 ../
drwxr-xr-x 4 cristy cristy 4096 Jan 4 07:00 emech-2.8.4-linux-static/
-rw-r--r-- 1 cristy cristy 309766 Apr 17 2002 emech-2.8.4-linux-static.tar.gz
EnergyMech bot. I thought eggdrops and ircq were being detected by cPanel during its nightly cleanup but i guess it doesnt look in hidden directories so that pretty useless.
Again, i just dont understand how Ensim can create an SSH environment where users are jailed to their own virtual domain webspace yet cPanel is unable to do this. Has anyone got any solutions to this. We really need this!!!!
Today i am searching my server looking for any damage that this idiot may have done.



LinkBack URL
About LinkBacks
Reply With Quote
== -1)




