The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Security A Security hole has been discovered in the cPanel's suexec/mod_php handlers.

Discussion in 'Security' started by Jedia, Jun 7, 2004.

  1. Jedia

    Jedia Well-Known Member

    Joined:
    Mar 18, 2004
    Messages:
    200
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    CN
     
  2. techark

    techark Well-Known Member

    Joined:
    May 22, 2002
    Messages:
    280
    Likes Received:
    0
    Trophy Points:
    16
    Don't update yet it breaks cpanel they say updating ot C10 will fix it but I am at C12 and all cpanel webmail etc url's are broke,.
     
  3. Choppy

    Choppy Member

    Joined:
    May 8, 2002
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    1
    Are you sure its working i just finished upgrading.. But only allow it to upgrade to stable.

    And everything is still broken. /cpanel/ /webmail/ etc etc.

    Regards
    Phillip
     
  4. nickn

    nickn Well-Known Member
    PartnerNOC

    Joined:
    Jun 15, 2003
    Messages:
    619
    Likes Received:
    1
    Trophy Points:
    18
    Make sure you are running C12...still broke on C12?
     
  5. Choppy

    Choppy Member

    Joined:
    May 8, 2002
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    1
    snickn

    techark says he is running C12 but still the same.

    Regards
    Phillip
     
  6. techark

    techark Well-Known Member

    Joined:
    May 22, 2002
    Messages:
    280
    Likes Received:
    0
    Trophy Points:
    16
    Updating to Edge fixed it.
     
  7. Choppy

    Choppy Member

    Joined:
    May 8, 2002
    Messages:
    10
    Likes Received:
    0
    Trophy Points:
    1
    So breaking other things or risking other things is a better solution?

    Hmm.

    Regards
    Phillip
     
  8. techark

    techark Well-Known Member

    Joined:
    May 22, 2002
    Messages:
    280
    Likes Received:
    0
    Trophy Points:
    16
    Hey I am not a happy camper either this is 3 rd time in 4 days I have had to complie Apache across 60 something servers.

    Getting kind of old if you know what I mean.

    Firstit was update to 1.3.1 right away then a few hours after I did that it was ModSSL has to be done now this.
     
  9. bman

    bman Well-Known Member

    Joined:
    Dec 28, 2003
    Messages:
    119
    Likes Received:
    0
    Trophy Points:
    16
    but for some one running stable cpanel he/she should not upgrade apache ?
    and to upgrade justy run buildapache and click build with out changeing the options ?
     
    #9 bman, Jun 8, 2004
    Last edited: Jun 8, 2004
  10. Dreamer

    Dreamer Well-Known Member

    Joined:
    Jun 23, 2003
    Messages:
    129
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    Bulgaria
    I'm on build 12 and /cpanel definetly works.
     
  11. techark

    techark Well-Known Member

    Joined:
    May 22, 2002
    Messages:
    280
    Likes Received:
    0
    Trophy Points:
    16
    The upgrade seems to have broken Front page on all our servers.

    ARCGHHHHHHH!!!!!
     
  12. bman

    bman Well-Known Member

    Joined:
    Dec 28, 2003
    Messages:
    119
    Likes Received:
    0
    Trophy Points:
    16
    i updated to WHM 9.4.0 cPanel 9.4.0-E13
    and did buildapache without changeing any options
    every thing seems working ok but did i need to change any options in buildapache ?
    or should i do /scripts/easyapache ?
    what option should i pick in /scripts/easyapache ? is it 5 or 1 ?
    thanks
     
  13. iko

    iko Well-Known Member
    PartnerNOC

    Joined:
    Jan 29, 2004
    Messages:
    56
    Likes Received:
    0
    Trophy Points:
    6
    I recommend not updating to a Current version. The STABLE tree is buggy enough to use buggier versions l
     
  14. kris1351

    kris1351 Well-Known Member

    Joined:
    Apr 18, 2003
    Messages:
    963
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    Lewisville, Tx
    Seems we have less trouble running current versions than any other. We have been keeping all servers on Current since March with no issues.
     
  15. rodolfochka

    rodolfochka Active Member

    Joined:
    Feb 1, 2004
    Messages:
    35
    Likes Received:
    0
    Trophy Points:
    6
    Location:
    Mexico City
    I just updgraded Apache and cpanel to this:
    WHM 9.4.0 cPanel 9.4.0-C12

    and is working fine, the url's are working fine.
    There is no error in the main page:
    Security There are no known security problems with the build of cPanel you are using!


    rodolfochka
     
  16. chash

    chash Member

    Joined:
    Jan 11, 2003
    Messages:
    8
    Likes Received:
    0
    Trophy Points:
    1
    check again - new front page

    Since this morning (9.40 - C12)

    there's a new front page module

    Hope the /webmail redirect gets fixed quick
     
  17. pweb

    pweb Registered

    Joined:
    Feb 18, 2004
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Tempe, AZ
    hmmm all this is confusing me.

    I did the upgrade few days ago, and all my PHP sites were down. I spent my Sunday fixing this.
    These are my current settings:
    WHM 9.2.0 cPanel 9.3.0-R5 and the Apache Core is the latest.

    Now I am still asked to update Apache, and Cpanel right after.

    Can somebody more experienced than me give some suggestions on what to do next?
    I am scared...

    tnx guys
     
  18. iko

    iko Well-Known Member
    PartnerNOC

    Joined:
    Jan 29, 2004
    Messages:
    56
    Likes Received:
    0
    Trophy Points:
    6
    update apache using /scripts/easyapache or buildapache in WHM. You may be haven't updated the mod_ssl.
     
  19. pweb

    pweb Registered

    Joined:
    Feb 18, 2004
    Messages:
    3
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Tempe, AZ
    tnx iko.

    The first time I just clicked on the link provided in whm... that goes to scripts/buildapache

    brainless.... do u suggest I run the script from the shell instead?
     
  20. verdon

    verdon Well-Known Member

    Joined:
    Nov 1, 2003
    Messages:
    836
    Likes Received:
    2
    Trophy Points:
    18
    Location:
    Northern Ontario, Canada
    cPanel Access Level:
    Root Administrator
    I've had better luck from shell... a little more confusing at first, but it tends not to time out and stop like my browser does :)
     
Loading...

Share This Page