The Community Forums

Interact with an entire community of cPanel & WHM users.
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

crack or bug

Discussion in 'General Discussion' started by ehsan, Jun 23, 2002.

  1. ehsan

    ehsan Well-Known Member

    Joined:
    Dec 11, 2001
    Messages:
    185
    Likes Received:
    0
    Trophy Points:
    16
    on one box we have reseller which DOES NOT have shell access, we usually dont give shell access to any body :)

    he resells predefined packages which they dont have shell access either.

    we found out he had setup an account recently trough his control panel and packages, which has shell access.

    well, there is only one 0 UID in passwd and ps is fine no sign for any crack or hack,

    Then i found out there are two other users that they have shell access too, they are created with root user,

    seems like some thing going on there...

    also it would be nice to have an option in modify account ( WHM ) to grant shell access or disable it.

    any idea on the problem?

    Thanks,
     
  2. ZachICU

    ZachICU Well-Known Member

    Joined:
    Aug 11, 2001
    Messages:
    130
    Likes Received:
    0
    Trophy Points:
    16
    If you want to disable all shell access, just modify your packages and it will update all accounts with those packages.

    If you want to easily switch between has shell or does not have shell you could create two packages with the same stats EXCEPT one has shell access and one doesnt.

    Then you can turn it off and on. :)

    Hope that helps you
    Zach
     
  3. ehsan

    ehsan Well-Known Member

    Joined:
    Dec 11, 2001
    Messages:
    185
    Likes Received:
    0
    Trophy Points:
    16
    well,

    thank you for reply

    actually that is not the problem, you can grant access or get shell access from a user manually from shell.

    problem is security issue, how thoes accounts have shell access while they are on no shell access package.
     
  4. SHSaeed

    SHSaeed Well-Known Member

    Joined:
    May 9, 2002
    Messages:
    245
    Likes Received:
    0
    Trophy Points:
    16
    Ehsan, in the reseller center, make sure you have these options checked/unchecked..

    [] Allow Creation of Packages with Shell Access
    [] All Features (warning: root access)
    [X] Never allow creation of accounts with shell access
    [] Account Modification (warning: this will allow circumvention of account creation limits, give shell access, dedicated ips, etc)
     
  5. ehsan

    ehsan Well-Known Member

    Joined:
    Dec 11, 2001
    Messages:
    185
    Likes Received:
    0
    Trophy Points:
    16
    Saeed,
    I have them all :)

    Nobody has shell access at all... getting scary...
     
  6. rpmws

    rpmws Well-Known Member

    Joined:
    Aug 14, 2001
    Messages:
    1,824
    Likes Received:
    5
    Trophy Points:
    38
    Location:
    back woods of NC, USA
    so did we find out if this was a &crack or bug& or a &crack in a bug& or maybe it is a &bug in a crack& ?
     
  7. ehsan

    ehsan Well-Known Member

    Joined:
    Dec 11, 2001
    Messages:
    185
    Likes Received:
    0
    Trophy Points:
    16
    well,
    we are sure it is a bug, but what kind we dont know yet
    might be bee or fly or something like that :)

    hopefully it is not benbug (new bug created by benladen)
    hehe

    ok, seriously, there is no answer yet, no guess for crack, we checked many things like possible changes in ps command or other monitoring parts.
    those accounts have never loged in to shell.
    It is a bug somewhere...
     
Loading...

Share This Page