Is there a reason for /usr/local/cpanel/src/3rdparty/gpl/mailman-2.1.3 to be owned by nobody instead of root?
This is another path writable by nobody with no noexec setting affecting it.
Also:
/usr/local/cpanel/src/3rdparty/bsd/imap-2002e-cpanel
And another...
/usr/local/urchin
All files under /usr/local/urchin are owned by nobody with rwx... this could allow a malicious user to remove urchin from the server.



LinkBack URL
About LinkBacks


Reply With Quote




