Welcome Guest. Please Login or Register  


You are here: Index > Softaculous Auto Installer > General Support > Topic : Apache symlink issue - vulnerable installations



Normal Mode | Print  

 Apache symlink issue - vulnerable installations (4 Replies, Read 2443 times)
random
Group: Member
Post Group: Newbie
Posts: 3
Status:
Hi,

Unfortunately, a vulnerability in Apache web servers means that a hacker who has managed to gain access to an account on a shared server can then gain access to all the files in all the other accounts on that server. More info on this vulnerability can be found at http://forums.cpanel.net/f185/how-prevent-creating-symbolic-links-non-root-users-202242.html

This vulnerability is being exploited by hackers to gain access to the configuration files of popular applications such as Wordpress and Joomla. One way to partially protect these applications is to change the permission given to their configuration files from 0644 to 0600.

Would Softaculous be willing to add a function in the settings to make it so that a hosting company can decide that all the configuration files for all applications are always set with a permission of 0600 when the server is making use of SuPHP?

This has already been implemented by one of your major competitor and would be an essential benefit from a security point of view. Failing to do so means that any installation set-up via Softaculous can be more easily compromised.

Thanks

Pascal
IP: --   


Threads
 random   Apache symlink issue - vulnerable installations (4 Replies, Read 2443 times)
    |--  Brijesh   Hi, Sir we...   on February 4, 2013, 5:48 am
    |--  random   Hi, That is...   on February 4, 2013, 6:09 am
    |--  random   Just one more...   on February 4, 2013, 8:21 am
    |--  Brijesh   Hi, No sir...   on February 4, 2013, 8:26 am

« Previous    Next »

Normal Mode | Print  



Users viewing this topic
1 guests, 0 users.


All times are GMT. The time now is May 7, 2025, 6:59 am.

  Powered By AEF 1.0.8 © 2007-2008 Electron Inc.Queries: 10  |  Page Created In:0.025