Current time: 04-24-2024, 11:53 PM Hello There, Guest! (LoginRegister)


Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Security hole in ISPCP 1.0.5
Author Message
kilburn Offline
Development Team
*****
Dev Team

Posts: 2,182
Joined: Feb 2007
Reputation: 34
Post: #12
RE: Security hole in ISPCP 1.0.5
Quote:use a security whole in a php- (or cgi)-app of one customer, upload a custom cgi, change the php.ini (if you want to continue with php)... etc
Hacking a website will give you access as the corresponding vuXXXX user (and you don't need to change the domain's php.ini for that). Anyway, vuXXXX users doesn't have access to the control panel (neither as reseller nor as user). Hence, hacking a website is not an attack vector to obtain admin/reseller credentials...

Quote:The server (kernel) was updated to the last stable versions of packets. I had installed & configured fail2ban, logwatch, blocked ports by iptables. I don't send my passwords by email and never published whole internet and my local machine. I don't know how he get the password to the reseller account.
I must insist that a reseller should not be able to run commands as root. Therefore, along with the reseller password stealing, the attacker *must* have used another attack to obtain root privileges (if he/she really obtained root privileges at all).

I'm starting to suspect that the server logs weren't really destroyed. It simply makes no sense at all for the attacker to spend so many time changing ftp account's passwords to replace the website's files if he had root access. Hence, I think that by "logfiles were destroyed" you are referring to the USER logfiles (those stored in /var/www/virtual/domain.com/logs) instead of the MACHINE logfiles (those in /var/log).
07-20-2010 08:32 PM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply 


Messages In This Thread
Security hole in ISPCP 1.0.5 - Alex Joe - 07-14-2010, 07:38 AM
RE: Security hole in ISPCP 1.0.5 - Nuxwin - 07-14-2010, 07:42 AM
RE: Security hole in ISPCP 1.0.5 - RatS - 07-14-2010, 05:38 PM
RE: Security hole in ISPCP 1.0.5 - ZooL - 07-15-2010, 06:31 AM
RE: Security hole in ISPCP 1.0.5 - gOOvER - 07-15-2010, 06:56 AM
RE: Security hole in ISPCP 1.0.5 - nuke3d - 07-16-2010, 06:36 PM
RE: Security hole in ISPCP 1.0.5 - kilburn - 07-16-2010, 07:39 PM
RE: Security hole in ISPCP 1.0.5 - joximu - 07-16-2010, 08:12 PM
RE: Security hole in ISPCP 1.0.5 - kilburn - 07-20-2010 08:32 PM
RE: Security hole in ISPCP 1.0.5 - nuke3d - 07-20-2010, 09:23 PM
RE: Security hole in ISPCP 1.0.5 - joximu - 07-20-2010, 11:16 PM

Forum Jump:


User(s) browsing this thread: 1 Guest(s)