Home  |  About  | Last |  Submit  |  Contact
AllQuests.com

Previous Question:  allow PHP to open sockets on server. Any danger  Technical Security IssuesNext Question:  Webmin MX Records  Technical Security Issues
Question Major security whole ( Web Hosting Talk Technical Security Issues )
Updated: 2008-11-20 18:10:01 (8)
Major security whole

Hi guys,

Most if not all of my server vBulletin installation were hacked a few times now. I was able to fix them all but this is being repeated a few times per day.

I know exactly how these kids are able to hack vBulletin installations. It's by uploading a CGI file and using the symlink function. I have just tested that and it worked immediately:

symlink("/home/username/public_html/vb/includes/config.php", "/home/anotherusername/public_html/con");

So the hackers are able to copy the config.php file then simply using the database name, username and password to alter the template table and display the hacking black screen.

How can we stop this from happening?

Your help on this issue is greatly appreciated as it's truly ruining our business.


EEssam

Answers: Major security whole ( Web Hosting Talk Technical Security Issues )
Major security whole

Well, first off, is your vbulletin installation up to date? Sounds like they are using an exploit to upload the file in the first place. And is this a dedicated machine, or are you on a shared server?

jphilipson

Major security whole

Hello,

We are offering shared hosting services for hundreds of people and we can't really prevent these files from being uploaded, we need them not to function after uploaded.

Thanks.

EEssam

Major security whole

Disable CGI on the account you use?

Dynash

Major security whole

Start using suphp / suexec and make sure each customer has a separate account?

The_Overl

Major security whole

Quote:
Originally Posted by The_Overl
Start using suphp / suexec and make sure each customer has a separate account?
suexec and suphp should stop users from linking to other users directories.

jphilipson

Major security whole

If you have cpanel, enable open basedir-restrictions. It will take care of your issue.

cascoing

Major security whole

If you're allowing file uploads you should have the program immediately change the name of the uploaded file to something random. That way it can't be accessed from outside.

WeWatch

Major security whole

In addition to having openbasedir restriction enabled, do make sure that insecure functions like
symlink is disabled from the server-wide php.ini file.
Also make sure that allow_url_fopen is disabled.

amalji

Previous Question:  allow PHP to open sockets on server. Any danger  Web Hosting Talk  Technical Security IssuesNext Question:  Webmin MX Records  Web Hosting Talk  Technical Security Issues

- Source: Major security whole Web Hosting Talk Technical Security Issues
- Previous Question: allow PHP to open sockets on server. Any danger Web Hosting Talk Technical Security Issues
- Next Question: Webmin MX Records Web Hosting Talk Technical Security Issues





AllQuests.com


Last queries: hostgator   bluehost   1and1   web hosting   dedicated server