The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

disabling CGI

Discussion in 'General Discussion' started by mehrdad abed, Dec 8, 2007.

  1. mehrdad abed

    mehrdad abed Well-Known Member

    Joined:
    Mar 18, 2006
    Messages:
    127
    Likes Received:
    0
    Trophy Points:
    16
    Hi

    I disabled CGI for an account from WHM, but cgi files still run on that account, what is the problem?

    apache 2.2
    php 5.2
    suphp
     
  2. ManojB

    ManojB Well-Known Member

    Joined:
    Mar 25, 2005
    Messages:
    80
    Likes Received:
    0
    Trophy Points:
    6
    Location:
    pune
    You can manually disable cgi-bin for your account by removing the following line in httpd.conf file

    ScriptAlias /cgi-bin/ /home/username/public_html/cgi-bin/
     
  3. mehrdad abed

    mehrdad abed Well-Known Member

    Joined:
    Mar 18, 2006
    Messages:
    127
    Likes Received:
    0
    Trophy Points:
    16
    thanks,

    Is there anyway to disable it for all users in one line ?
     
  4. agressor

    agressor Active Member

    Joined:
    May 15, 2005
    Messages:
    34
    Likes Received:
    0
    Trophy Points:
    6
    recompile apache without support for cgi.
     
  5. mehrdad abed

    mehrdad abed Well-Known Member

    Joined:
    Mar 18, 2006
    Messages:
    127
    Likes Received:
    0
    Trophy Points:
    16
    I removed this line in httpd.conf for an account :

    ScriptAlias /cgi-bin/ /home/username/public_html/cgi-bin/

    but cgi could be run in any other directory with these options in .htaccess :

    Options +ExecCGI
    AddHandler cgi-script .cgi .pl

    I really dont know how to disable cgi for an account in this new cPanel :confused:
     
  6. mehrdad abed

    mehrdad abed Well-Known Member

    Joined:
    Mar 18, 2006
    Messages:
    127
    Likes Received:
    0
    Trophy Points:
    16
    No body knows ?
     
  7. activa

    activa Well-Known Member

    Joined:
    May 23, 2006
    Messages:
    204
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    Morocco
    cPanel Access Level:
    Root Administrator
    the same probleme .

    how we can disable cgi-bin from all account or disable running perl script in accounts users .

    thanks
     
  8. agressor

    agressor Active Member

    Joined:
    May 15, 2005
    Messages:
    34
    Likes Received:
    0
    Trophy Points:
    6
    i have the same problem... :(
     
  9. activa

    activa Well-Known Member

    Joined:
    May 23, 2006
    Messages:
    204
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    Morocco
    cPanel Access Level:
    Root Administrator
    up up up ..

    anyone for this !!
     
  10. activa

    activa Well-Known Member

    Joined:
    May 23, 2006
    Messages:
    204
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    Morocco
    cPanel Access Level:
    Root Administrator
    i have solved this probleme with mod_security .

    in the config rules of the mode_security find the fallowing


    Code:
    # removed exe so that frontpage will work
    SecRule REQUEST_BASENAME "\.(?:c(?:o(?:nf(?:ig)?|m)|s(?:proj|r)?|dx|er|fg|md)|p(?:rinter|ass|db|ol|wd)|v(?:b(?:proj|s)?|sdisco)|a(?:s(?:ax?|cx)|xd)|s(?:html?|ql|tm|ys)|d(?:bf?|at|ll|os)|i(?:d[acq]|n[ci])|ba(?:[kt]|ckup)|res(?:ources|x)|l(?:icx|nk|og)|\w{,5}~|webinfo|ht[rw]|xs[dx]|key|mdb|old)$" \

    adding the pl extention will prevent perl script from running like this :

    Code:
    # removed exe so that frontpage will work
    SecRule REQUEST_BASENAME "\.(?:c(?:o(?:nf(?:ig)?|m)|s(?:proj|r)?|dx|er|fg|md)|p(?:rinter|ass|db|ol|wd)|v(?:b(?:proj|s)?|sdisco)|a(?:s(?:ax?|cx)|xd)|s(?:html?|ql|tm|ys)|d(?:bf?|at|ll|os)|i(?:d[acq]|n[ci])|ba(?:[kt]|ckup)|res(?:ources|x)|l(?:icx|nk|og)|\w{,5}~|webinfo|ht[rw]|xs[dx]|key|mdb|old|pl)$" \
    i hope that can be usefull for all
     
  11. myBox

    myBox Active Member

    Joined:
    Jan 6, 2004
    Messages:
    40
    Likes Received:
    0
    Trophy Points:
    6
    I think if you disabled mod_cgi.c from the apache build this will disabled CGI all together.

    but I am not sure yet I did not test it.
     
Loading...

Share This Page