Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 1 of 3 1 2 3 LastLast
Results 1 to 15 of 38
  1. #1
    cPanel Partner NOC cPanel Partner NOC Badge cyon's Avatar
    Join Date
    Jan 2003
    Posts
    323

    Default XML RPC Exploit

    There is a critical exploit for xml rpc for php. (see http://www.gulftech.org/?node=resear...00088-07022005 for details)

    I just reported the bug in bugzilla. please vote on it, if you want to have it fixed asap: http://bugzilla.cpanel.net/show_bug.cgi?id=2768

    edit: on WHT is a discussion about it: http://www.webhostingtalk.com/showth...hreadid=421520
    Last edited by cyon; 07-04-2005 at 07:53 PM.

  2. #2
    Member
    Join Date
    Jun 2005
    Posts
    159

    Default

    26 views and 3 votes (I just voted). It will only take a minute of your time, please vote.

  3. #3
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    looks like on 7/05/05 a new buildapache is listed on layer1 .. but i don't see a new version of php listed in the whm script yet.
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  4. #4
    Member
    Join Date
    Dec 2001
    Posts
    1,558

    Default

    Keep in mind people that PHP have NOT updated a stable release yet, only an RC2. The change to Buildapache was most likely the updating of the pear module, though I can not confirm this.

    http://www.php.net/ <-- install it manually if you must, but keep in mind it is RC2. I'm sure the more people that QA it, the faster it will be released.
    Beau Henderson

  5. #5
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Remember that also the scripts using embedded xml-rpc classes need to be updated, like Wordpress:

    http://codex.wordpress.org/Changelog/1.5.1.3

  6. #6
    Registered User
    Join Date
    Dec 2002
    Posts
    3

    Default

    any updates from cPanel for a fix to this?

  7. #7
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    As haze has said, cPanel are unlikely to release a fix until there's a stable PHP release for it. If you want a specific response from them you should contact them following the details on their site.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  8. #8
    Member
    Join Date
    Mar 2002
    Location
    San Francisco
    Posts
    257

    Default

    WHT forums thread on sam esubject here: http://www.webhostingtalk.com/showth...67#post3212267

    darksoul suggested this for mod_sec rules:

    SecFilter "xmlrpc.php"

  9. #9
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    From php.net

    An easily exploitable security issue was discovered in PEAR XML_RPC <= 1.3.0. We recommend that users of this PEAR class immediately upgrade to the latest version with:

    pear upgrade XML_RPC

    The same security problem exists in many other XML RPC implementations, please check if the installed applications that you use might have a similar problem.

  10. #10
    cPanel Partner NOC cPanel Partner NOC Badge cyon's Avatar
    Join Date
    Jan 2003
    Posts
    323

    Default

    Quote Originally Posted by chirpy
    As haze has said, cPanel are unlikely to release a fix until there's a stable PHP release for it. If you want a specific response from them you should contact them following the details on their site.
    In my eyes it's much more dangerous to wait for a stable version than to upgrade to an unstable one.

    What's more worse, beeing attacked through the exploit or having some issues with an unstable version?
    Last edited by cyon; 07-05-2005 at 03:12 PM.

  11. #11
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    I don't disagree. However, that has been cPanel's stance in the past and the recent issues after doing exactly what you suggest with proftpd (and all the problems that caused) probably reinforces that viewpoint.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  12. #12
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Some more info about vulnerable cms/blog software:

    http://forum.hardened-php.net/viewtopic.php?id=9

  13. #13
    cPanel Partner NOC cPanel Partner NOC Badge trparky's Avatar
    Join Date
    Apr 2003
    Posts
    190

    Default

    Does Apache/PHP need to be recompiled to fix this or is this a PHP Pear Module issue?
    Tom Parkison – Rochen Ltd. – tom@rochen.com
    - Reseller Plans & Multiple Domain Solutions
    - http://www.rochen.com

  14. #14
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Quote Originally Posted by trparky
    Does Apache/PHP need to be recompiled to fix this or is this a PHP Pear Module issue?
    Did you bother reading all the posts ? For now upgrade pear xml rpc and all the xmlrpc files used by blog/cms software. Do a search for *xml*rpc* on your servers and you'll have an idea

    The final step is to wait for the next stable php release, and this is only necessary if you have compiled php with --xml-rpc

  15. #15
    cPanel Partner NOC cPanel Partner NOC Badge trparky's Avatar
    Join Date
    Apr 2003
    Posts
    190

    Default

    I did that, and yes, a few of the servers we run have the compile switch "--xml-rpc". Wonderful, that is great!

    When will PHP come out with a fix for this?

    I was getting confused because there are two XML-RPC-like modules. One Pear and one built into PHP. Are all PHP implementations vulnerable to this attack?
    Last edited by trparky; 07-05-2005 at 05:33 PM.
    Tom Parkison – Rochen Ltd. – tom@rochen.com
    - Reseller Plans & Multiple Domain Solutions
    - http://www.rochen.com

Similar Threads & Tags
Similar threads

  1. Horde Groupware SyncML and rpc.php
    By ElrondBCN in forum E-mail Discussions
    Replies: 2
    Last Post: 06-20-2011, 06:10 AM
  2. Get in the cpanel codeigniter using xml-rpc
    By zerutreck in forum cPanel Developers
    Replies: 1
    Last Post: 03-25-2009, 03:28 PM
  3. xml-rpc
    By yourwayit in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-08-2006, 10:33 AM
  4. rpc.statd
    By AbeFroman in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-04-2004, 01:04 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube