Found Script That Can Open other User home directory
Hello,
Today i found someone upload a script that can open other user home directory.
the script like this:
- Removed -
I tried to run this script at pay shared hosting, seems it block it and only show black screen.
But when i try to run it at my server, the script is open, and show all entire home directory, and it can get Wordpress config file.
How i can prevent a script like this to be running on my server?
-
Bellow i attached some screen for cPanel team to investigate it: - Removed - This script can open your main root directory / 0 -
No need to post the script or screenshots, these sorts of scripts have been around forever. You might consider this script by ConfigServer for assistance with preventing this sort of thing from being uploaded to your server: ConfigServer eXploit Scanner (cxs) There are others as well. 0 -
No need to post the script or screenshots, these sorts of scripts have been around forever. You might consider this script by ConfigServer for assistance with preventing this sort of thing from being uploaded to your server: ConfigServer eXploit Scanner (cxs) There are others as well.
Okay, thanks for your information, is there other alternative than cxs that comes for free?0 -
Yes, but I don't have any additional links to share, I swear by this one. Worth every penny. 0 -
Yes, but I don't have any additional links to share, I swear by this one. Worth every penny.
yes i know it worth, but this with my office, throw out money was easy by them, but to take it out, need time, around 1 month or a year. Well you know that was Office Administration. And meanwhile i can't wait for that long.0 -
YMMV: Linux Malware Detect - R-fx Networks
Hi thanks, i have use and configure it. but seems not work for that script. since when i try to run that script, it keep open0 -
First, remove that script from your server, stop running it. Those scripts phone home. Second, change your passwords. No telling what you've already sent by running the script (read: opened it on your server). Third, find the 60 bucks to get the other script I suggested, whats your server worth to you?? And finally, if you need additional security assistance and are not sure what to do, you should hire a professional: System Administration Services | cPanel Forums 0 -
Hello, You may also find the following documents helpful, especially if the script you are referring to takes advantage of symbolic links: Symlink Race Condition Protection - EasyApache - cPanel Documentation How to Harden Your cPanel System's Kernel - cPanel Knowledge Base - cPanel Documentation Security - cPanel Knowledge Base - cPanel Documentation Thank you. 0 -
Also, I would suggest you install and configure Cloudlinux for some extra security. 0 -
Also, I would suggest you install and configure Cloudlinux for some extra security.
hi thanks for your sugestion, i will think about it0 -
Also, I would suggest you install and configure Cloudlinux for some extra security.
Cloudlinux is good option, but security is depending on your configurations :D0
Please sign in to leave a comment.
Comments
13 comments