nuke3d
Junior Member
Posts: 107
Joined: Sep 2007
Reputation: 1
|
RE: Security hole in ISPCP 1.0.5
Even if he had root access, how would he find out the admin panel login? Do you have the same passwords for root & admin (or admin/reseller, or root/reseller)?
I think one possibility to execute commands as root would be if the files in /var/www/ispcp could somehow be accessed with write permissions through an exploit in ispcp or another service that you might have running. Still courious why he wouldn't just set a new password for root an be done with it, though.
|
|
07-20-2010 09:23 PM |
|