Welcome Guest. Please Login or Register  


You are here: Index > Webuzo > General Support > Topic : Security Issue (LEMP)



Threaded Mode | Print  

 Security Issue (LEMP), With LEMP installed, anyone can download my server files. (9 Replies, Read 12281 times)
vectorman
Group: Member
Post Group: Newbie
Posts: 2
Status:
Hello,

I hope this has not already been addressed elsewhere (I did a search and could not find a similar issue.)

I really am liking Webuzo a lot. I am just having one issue:

I've installed the LEMP stack (and removed Apache/LAMP). When I view my website (that I've added) by its domain, it works fine.  But then I typed 'hxxp://myserverip/~user'  to list all of the files on my site. I discovered that clicking any of these files (including PHP files) will download them, instead of serving them. I can also type hxxp://myserverip/~user/myPhpFile.php and it will also start downloading the file as well.

Ideally, the files will simply be served (like it does when using the domain).

Any help with this issue is appreciated.


IP: --   

Security Issue (LEMP)
valley
Group: Webuzo Team
Post Group: Super Member
Posts: 1644
Status:
Sir we shall replicate the issue on our servers and serve you with with a solution as soon as possible.

-----------------------
Webuzo : Single User Control Panel
Join Webuzo :
Facebook
Twitter

IP: --   

Security Issue (LEMP)
vectorman
Group: Member
Post Group: Newbie
Posts: 2
Status:
Thank, I appreciate it :) .
IP: --   

Security Issue (LEMP)
pinoyjunction
Group: Member
Post Group: Newbie
Posts: 17
Status:
Thanks for pointing that out. I am new to Webuzo and I love the features but this issue is a big problem. I can also access all the files when browsing xxx.xxx.xxx-ip/~user.

Any solution for this problem?

Sorry for my bad english.
IP: --   

Security Issue (LEMP)
valley
Group: Webuzo Team
Post Group: Super Member
Posts: 1644
Status:
Quote From : pinoyjunction February 14, 2014, 3:43 pm
Thanks for pointing that out. I am new to Webuzo and I love the features but this issue is a big problem. I can also access all the files when browsing xxx.xxx.xxx-ip/~user.

Any solution for this problem?

Sorry for my bad english.


Are you facing this issue on Apache or NGINX ?


-----------------------
Webuzo : Single User Control Panel
Join Webuzo :
Facebook
Twitter

IP: --   

Security Issue (LEMP)
pinoyjunction
Group: Member
Post Group: Newbie
Posts: 17
Status:
Hello Sir,

I installed LEMP and used nginx as webserver.
IP: --   

Security Issue (LEMP)
divij
Group: Member
Post Group: Elite Member
Posts: 290
Status:
Hi,

Sir open a support ticket with your server root detail.
We will apply the fix on your server .
IP: --   

Security Issue (LEMP)
pinoyjunction
Group: Member
Post Group: Newbie
Posts: 17
Status:
Okay, thanks. Opening a support ticket now. :)
IP: --   

Security Issue (LEMP)
pinoyjunction
Group: Member
Post Group: Newbie
Posts: 17
Status:
I can't edit my post so I think I have to make a new one.

I have already uninstalled webuzo, do I have to reinstall it again or are you just giving me the details on how to secure it? Thanks
IP: --   

Security Issue (LEMP)
valley
Group: Webuzo Team
Post Group: Super Member
Posts: 1644
Status:
Webuzo will be required to be installed on your server so that we can provide you the patch.

-----------------------
Webuzo : Single User Control Panel
Join Webuzo :
Facebook
Twitter

IP: --   

« Previous    Next »

Threaded Mode | Print  



Jump To :


Users viewing this topic
1 guests, 0 users.


All times are GMT. The time now is April 29, 2024, 4:51 am.

  Powered By AEF 1.0.8 © 2007-2008 Electron Inc.Queries: 11  |  Page Created In:0.023