The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Found Script That Can Open other User home directory

Discussion in 'Security' started by hrace009, Oct 13, 2016.

  1. hrace009

    hrace009 Well-Known Member

    Joined:
    Dec 24, 2013
    Messages:
    68
    Likes Received:
    8
    Trophy Points:
    8
    Location:
    Root
    cPanel Access Level:
    Root Administrator
    Twitter:
    Hello,

    Today i found someone upload a script that can open other user home directory.
    the script like this:

    - Removed -

    I tried to run this script at pay shared hosting, seems it block it and only show black screen.
    But when i try to run it at my server, the script is open, and show all entire home directory, and it can get Wordpress config file.
    How i can prevent a script like this to be running on my server?
     
    #1 hrace009, Oct 13, 2016
    Last edited by a moderator: Oct 14, 2016
  2. hrace009

    hrace009 Well-Known Member

    Joined:
    Dec 24, 2013
    Messages:
    68
    Likes Received:
    8
    Trophy Points:
    8
    Location:
    Root
    cPanel Access Level:
    Root Administrator
    Twitter:
    Bellow i attached some screen for cPanel team to investigate it:
    - Removed -

    This script can open your main root directory /
     
  3. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,448
    Likes Received:
    195
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    No need to post the script or screenshots, these sorts of scripts have been around forever.

    You might consider this script by ConfigServer for assistance with preventing this sort of thing from being uploaded to your server:
    ConfigServer eXploit Scanner (cxs)

    There are others as well.
     
  4. hrace009

    hrace009 Well-Known Member

    Joined:
    Dec 24, 2013
    Messages:
    68
    Likes Received:
    8
    Trophy Points:
    8
    Location:
    Root
    cPanel Access Level:
    Root Administrator
    Twitter:
    Okay, thanks for your information, is there other alternative than cxs that comes for free?
     
  5. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,448
    Likes Received:
    195
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    Yes, but I don't have any additional links to share, I swear by this one. Worth every penny.
     
  6. hrace009

    hrace009 Well-Known Member

    Joined:
    Dec 24, 2013
    Messages:
    68
    Likes Received:
    8
    Trophy Points:
    8
    Location:
    Root
    cPanel Access Level:
    Root Administrator
    Twitter:
    yes i know it worth, but this with my office, throw out money was easy by them, but to take it out, need time, around 1 month or a year. Well you know that was Office Administration. And meanwhile i can't wait for that long.
     
  7. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,448
    Likes Received:
    195
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
  8. hrace009

    hrace009 Well-Known Member

    Joined:
    Dec 24, 2013
    Messages:
    68
    Likes Received:
    8
    Trophy Points:
    8
    Location:
    Root
    cPanel Access Level:
    Root Administrator
    Twitter:
    Hi thanks, i have use and configure it. but seems not work for that script. since when i try to run that script, it keep open
     
  9. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,448
    Likes Received:
    195
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    First, remove that script from your server, stop running it. Those scripts phone home. Second, change your passwords. No telling what you've already sent by running the script (read: opened it on your server). Third, find the 60 bucks to get the other script I suggested, whats your server worth to you??

    And finally, if you need additional security assistance and are not sure what to do, you should hire a professional:
    System Administration Services | cPanel Forums
     
  10. hrace009

    hrace009 Well-Known Member

    Joined:
    Dec 24, 2013
    Messages:
    68
    Likes Received:
    8
    Trophy Points:
    8
    Location:
    Root
    cPanel Access Level:
    Root Administrator
    Twitter:
    cPanelMichael likes this.
  11. weetabix

    weetabix Well-Known Member

    Joined:
    Oct 26, 2006
    Messages:
    56
    Likes Received:
    1
    Trophy Points:
    8
    Also, I would suggest you install and configure Cloudlinux for some extra security.
     
  12. hrace009

    hrace009 Well-Known Member

    Joined:
    Dec 24, 2013
    Messages:
    68
    Likes Received:
    8
    Trophy Points:
    8
    Location:
    Root
    cPanel Access Level:
    Root Administrator
    Twitter:
    hi thanks for your sugestion, i will think about it
     
  13. torrent4all

    torrent4all Member

    Joined:
    Oct 19, 2016
    Messages:
    5
    Likes Received:
    1
    Trophy Points:
    3
    cPanel Access Level:
    Root Administrator
    Cloudlinux is good option, but security is depending on your configurations :D
     
Loading...

Share This Page