Softaculous


Topic : security


Posted By: coolmates on July 26, 2014, 9:16 am
my web host wont enable their resellers access to add custom scripts to the auto installer and wont add our custom scripts either because they are afraid about the security issues this poses on shared servers

what reassurances can you give that no-one can add any such potentially malicious script?

Posted By: Brijesh on July 26, 2014, 10:19 am | Post: 1
Hi,

At the moment it is possible to add a custom script only from Softaculous Admin panel which is accessible only with root access.

-----------------------
Webuzo - Multi User Hosting Control Panel
AMPPS - Best WordPress/PHP/MySQL development tool

Posted By: coolmates on July 26, 2014, 10:47 am | Post: 2
i know that. but my host disables the ability to add custom scripts and wont add them themselves.

please confine your responses to the actual question asked. the above reply does not address the issue raised and has no relation to it in any way.

Posted By: Brijesh on July 28, 2014, 7:24 am | Post: 3
Hi,

Regarding reassurance that no-one can add malicious script, while adding a script to Softaculous we thoroughly review the script to make sure malicious script is not added.

In case of a custom script since you are add it manually we do not have access to that script hence it cannot be verified by us hence the option to add custom script is restricted only to root.

-----------------------
Webuzo - Multi User Hosting Control Panel
AMPPS - Best WordPress/PHP/MySQL development tool

Posted By: coolmates on July 28, 2014, 9:38 am | Post: 4
in that case, what happens to a custom script when i add it to a vps/dedicated server which has a licened copy of Softaculous installed?

Posted By: Brijesh on July 29, 2014, 10:07 am | Post: 5
Hi,

Since it is a custom script, before you add the custom script you will have to make sure that it does not have malicious code.

-----------------------
Webuzo - Multi User Hosting Control Panel
AMPPS - Best WordPress/PHP/MySQL development tool

Powered By AEF 1.0.8 © 2007-2008 Electron Inc.