LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - News > Syndicated Linux News
User Name
Password
Syndicated Linux News This forum is for the discussion of Syndicated Linux News stories.

Notices


Reply
  Search this Thread
Old 08-28-2020, 03:42 PM   #1
LXer
LXer NewsBot
 
Registered: Dec 2005
Posts: 128,646

Rep: Reputation: 118Reputation: 118
LXer: How to Protect Your cPanel Server from Backdoor Access, Plus a Warning for the Disabled Shell Access Setting in WHM


Published at LXer:

A hacker can gain command line access to their cPanel account even after you've suspended it, additionally, they can get shell access even if you have disabled it in WebHost Manager (WHM).

Read More...
 
Old 08-28-2020, 05:53 PM   #2
greencedar
Senior Member
 
Registered: Sep 2018
Distribution: Linux Mint 19.1 Tessa & 19.3 Tricia
Posts: 1,314
Blog Entries: 1

Rep: Reputation: 128Reputation: 128
Very serious article on a security issue concerning the cPanel on a Web Host Manager (WHM).

Here is the author's summation with a Disclaimer that needs to be read.

Quote:
In summary, we covered two issues within the cPanel software which can lead to escalated access. The first being able to regain access to a suspended account and the second, being able to use one of two methods to get shell access, even its set to disabled in WHM. We also covered how to block the first method using hooks and we gave some tips on possible ways to catch the second method. Currently both vulnerabilities have not been corrected by the vendor, please refer to the cPanel change log: docs.cpanel.net/changelogs/ to see if a fix has been released.

Disclaimer: Code snippets and scripts are for informational purposes only, may not appear correctly, and have not been thoroughly tested, do not use in production.
If there are any thoughts, or examples of cPanel security issues, that anyone would like to discuss on this article I would like to hear them.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: How to upgrade your VPS cPanel/WHM version from command line? LXer Syndicated Linux News 0 06-02-2015 01:06 AM
Cpanel/WHM Died at /usr/local/cpanel/Cpanel/Hulk.pm line 92. liang3391 Linux - Software 1 06-22-2009 02:02 PM
cpanel/whm initial setup - Do I need a separate DNS server? jlgreer1 Linux - Server 5 06-08-2008 09:24 AM
unexpected reboot - linux server - centos 5.1 - cPanel / WHM GiotisSL Linux - Server 1 03-28-2008 05:42 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - News > Syndicated Linux News

All times are GMT -5. The time now is 02:59 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration