Security Advisory: ProFTPD

MattDees

Well-Known Member
Apr 29, 2005
416
1
243
Houston, TX
cPanel Access Level
Root Administrator
Due to a vulnerability in ProFTPD we are advising that everyone use PureFTPd untill we roll out a patch. The patch will be rolled out as soon as we possible can (I will post in this thread when we do so)
 

eth00

Well-Known Member
PartnerNOC
Mar 30, 2003
721
1
168
NC
cPanel Access Level
Root Administrator
Thanks for the info, just talked with Billy and he confirmed this is an issue.

*edit* now matt is atleast on the staff group so looks legit.
 
C

cPanelBilly

Guest
We are still waiting on the full testing to be done as soon as it is it will be rolled out to the rest as soon as testing is done.
 
C

cPanelBilly

Guest
It is currently in:
BETA, EDGE, CURRENT

If all goes well it will be in RELEASE monday and then STABLE on wed.
 

knipper

Well-Known Member
Sep 4, 2001
107
0
316
Hey all...
I am currently running WHM 10.1.0 cPanel 10.2.0-R82 and when updates ran last night it completely broke proftd ( I hadn't seen this thread so no change was made)

Was proftpd disabled by cPanel, or was a patch implemented which caused problems for me?

I am going to change now to pure-ftpd and see if ftpd will run. Anyone else have issues today?
 

knipper

Well-Known Member
Sep 4, 2001
107
0
316
OK.... looks like I have a problem. I tried twice to switch from proftpd to pure-ftpd via the Tweak FTP menu within WHM. When I click to "switch to pure-ftpd" I get the normal page loading, etc. But it seems to just hang... first time I let it go about 10 mins.... tried to restart ftpd but didn't work.

Tried to use the switch button again.... this time waited 15-20mins to no avail.

What would the command be (for the script) to switch from within shell/root so I can see whats happening?

Thanks in advance.
 

knipper

Well-Known Member
Sep 4, 2001
107
0
316
Thanks eth00...

Looks like it didin't need to do it after all via root. When I logged in I first took a look at the logs, and saw one of my clients had logged in via pure-ftpd just minutes before and was successfull. I ran a couple FTP log-in tests and it seemed to be working.

I went back to WHM, to tweak FTP and it showed Pure-ftpd was now being used.

Just not sure why to took so long in WHM, and never did actually see any type of success message.
 

PbG

Well-Known Member
Mar 11, 2003
247
0
166
Why isn't this NOTICE in WHM news?? Furthermore why can't we select whether we want news or icons to load by default?
 

PbG

Well-Known Member
Mar 11, 2003
247
0
166
I did that too.

Aric1 said:
You should make your requests in bugzilla, so they have them on record.

The WHM news is almost never updated.

Aric