ehsan

Well-Known Member
Dec 11, 2001
185
0
316
on one box we have reseller which DOES NOT have shell access, we usually dont give shell access to any body :)

he resells predefined packages which they dont have shell access either.

we found out he had setup an account recently trough his control panel and packages, which has shell access.

well, there is only one 0 UID in passwd and ps is fine no sign for any crack or hack,

Then i found out there are two other users that they have shell access too, they are created with root user,

seems like some thing going on there...

also it would be nice to have an option in modify account ( WHM ) to grant shell access or disable it.

any idea on the problem?

Thanks,
 

ZachICU

Well-Known Member
Aug 11, 2001
130
0
316
If you want to disable all shell access, just modify your packages and it will update all accounts with those packages.

If you want to easily switch between has shell or does not have shell you could create two packages with the same stats EXCEPT one has shell access and one doesnt.

Then you can turn it off and on. :)

Hope that helps you
Zach
 

ehsan

Well-Known Member
Dec 11, 2001
185
0
316
well,

thank you for reply

actually that is not the problem, you can grant access or get shell access from a user manually from shell.

problem is security issue, how thoes accounts have shell access while they are on no shell access package.
 

SHSaeed

Well-Known Member
May 9, 2002
245
0
316
Ehsan, in the reseller center, make sure you have these options checked/unchecked..

[] Allow Creation of Packages with Shell Access
[] All Features (warning: root access)
[X] Never allow creation of accounts with shell access
[] Account Modification (warning: this will allow circumvention of account creation limits, give shell access, dedicated ips, etc)
 

ehsan

Well-Known Member
Dec 11, 2001
185
0
316
Saeed,
I have them all :)

Nobody has shell access at all... getting scary...
 

rpmws

Well-Known Member
Aug 14, 2001
1,822
8
318
back woods of NC, USA
so did we find out if this was a &crack or bug& or a &crack in a bug& or maybe it is a &bug in a crack& ?
 

ehsan

Well-Known Member
Dec 11, 2001
185
0
316
well,
we are sure it is a bug, but what kind we dont know yet
might be bee or fly or something like that :)

hopefully it is not benbug (new bug created by benladen)
hehe

ok, seriously, there is no answer yet, no guess for crack, we checked many things like possible changes in ps command or other monitoring parts.
those accounts have never loged in to shell.
It is a bug somewhere...