Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 15 of 15
  1. #1
    Member
    Join Date
    Feb 2003
    Posts
    205

    Unhappy Wow Another Major Bug!

    A client has just found another major bug. Its been verified by us this has the potential to ruin alot of accounts (if you offer reseller accounts mostly) but it could affect virtualhosting also.

    Basically say you create a new username "billy" then at a later stage a reseller/you creates another account "billy-" .

    "billy-" has access to all of "billy" 's mysql data. Not sure about the other stuff however mysql is more than enough and users that our out with a vengence can wreck havoc on servers.

    Has anyone else seen this happen before?

  2. #2
    Member
    Join Date
    Feb 2003
    Posts
    190

    Default

    Testing it now here. It definately shows mysql data, but I can't get access to anything else.

  3. #3
    Member
    Join Date
    Feb 2003
    Posts
    190

    Default

    if you create an account to test it out, don't delete it! It'll take the orginal acconut holder's database with it when it is deleted.

    That's the most disturbing part of this...anyone can delete any database on the machine that they choose just by creating an account and deleting it.

  4. #4
    Member
    Join Date
    Feb 2003
    Posts
    205

    Default

    Thanks our user asked that question I didn't check it on a test account. This is quite disturbing.

  5. #5
    Member
    Join Date
    Feb 2003
    Posts
    205

    Default

    Maybe the next version address's this problem?

  6. #6
    Member trakwebster's Avatar
    Join Date
    Jan 2003
    Posts
    145

    Default Close the door - the burgler doesn't matter.

    Originally posted by thaphantom
    submit a bug report... dont know how much can be done about this as it appears to be a mysql problem...
    Hi, thaphantom,

    Actually, the cpanel flaw here -- and one which should be modestly easy for them to fix -- is that on a given server, nobody should be able to create a new user with the same name as an existing user.

    The ability to have two same-name or functionally-same-name users has just got to lead to difficulties.

    And the simplest case of mistaken identity can cause damage. So it would seem that if 'billy' is on the server, then billy-, billyboy, and billygoat need to be blocked, if they are functionally the same anywhere.

    Or, as robocop says, 'There will be ... trouble.'

    -- Arthur Cronos from Voltos
    -- Arthur Cronos from Voltos
    =================================================
    The Bloggard, Un Hombre Muy Blogisto -- http://www.bloggard.com
    Your loch ness monster, your yeti, your bigfoot. Bah! I've seen worse.
    =================================================

  7. #7
    Member
    Join Date
    Nov 2002
    Location
    Delaware
    Posts
    67

    Default Reply:

    Not sure why this would happen either. Cpanel shouldn't let databases be deleted since billy and billy- should both have seperate passwords. This would seem to be a cpanel issue to me.

    I know in the past that uses can upload phpmyadmin and set the login as root and is then able to view all databases on the server. You can also look at most of the contents in the db's if you really know your way around but you can't modify anything without the password though so this should be the same no matter what username you are using.

    My thoughts anyway.
    Chris
    Last edited by sitehostz; 03-10-2003 at 02:18 AM.

  8. #8
    Registered User
    Join Date
    Feb 2003
    Posts
    4

    Default

    Wow another one.

    Thanks for the heads up

  9. #9
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Feb 2003
    Posts
    16

    Default

    I knew this issue for a while already, it's on since the beginning.
    mysql username or database creation ignores the - char and thus, that creates a problem.

  10. #10
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Mar 2002
    Posts
    33

    Default

    I was just thinking about this bug some more. What would happen if someone made a user called "root-" ?

  11. #11
    Member Brad's Avatar
    Join Date
    Aug 2001
    Posts
    236

    Default

    Did someone already submit this bug?

  12. #12
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,597

    Default

    mysql doesn't allow -s in db names. The flip side of this is that the only way to fix it is to disable -s in usernames.

  13. #13
    Member
    Join Date
    Mar 2003
    Posts
    31

    Default phpmyadmin error

    Warning: Failed opening './libraries/auth/http.auth.lib.php' for inclusion (include_path='/usr/local/cpanel/3rdparty/lib/php/') in /usr/local/cpanel/base/3rdparty/phpMyAdmin/libraries/common.lib.php on line 569

    Fatal error: Call to undefined function: pma_auth_check() in /usr/local/cpanel/base/3rdparty/phpMyAdmin/libraries/common.lib.php on line 570

    anyone heard of this error?
    , when you click on the phpmyadmin button.
    I have a serverside problem. phpmyadmin doesnt work.

    can anyone please help !!!
    visiondream3

  14. #14
    Registered User
    Join Date
    Feb 2003
    Posts
    2

    Thumbs up

    visiondream.. i have fixed the issue. The permissions and the ownerships of the files in the folder /usr/local/cpanel/base/3rdparty/phpMyAdmin
    were wrong. The ownership should be
    cpanel.cpanel and the permissions should be 700
    That did the trick.

  15. #15
    cPanel Staff cpanelnick's Avatar
    Join Date
    Feb 2003
    Location
    Houston, TX
    Posts
    4,597

    Default

    ok
    6.2.0 builds don't allow you to add a user with a - in them if there is a username that would be the same as the user without the - in it.

Similar Threads & Tags
Similar threads

  1. Replies: 16
    Last Post: 06-03-2006, 12:44 AM
  2. .htaccess and .wmv Major Bug?
    By Planet_Master in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 09-03-2005, 04:29 PM
  3. WOW! Bandwidth bug? EXCEEDED BY 4153%?
    By iHost.net.nz in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 09-24-2004, 12:24 AM
  4. Major Email Bug in CPanel
    By pete3005 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 11-20-2001, 07:34 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube