Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Website and Server Administration Forum


You are currently viewing our Website and Server Administration Forum as a guest. Please register to participate.
Login



Reply
possible VPS security issue
Old 07-07-2010, 06:28 AM possible VPS security issue
Junior Talker

Posts: 2
Trades: 0
I am hoping that someone might have some insight into an issue that I came across today while working on one of my clients websites that I am building for him. I was setting up a FileManager and Image uploader to be part of CKEditor for the backend updating of his website - - - when I entered var fileRoot = '/'; in the variable for the directory that I want to display for managing the files on his account, the complete file structure of my VPS ROOT displayed and I was able to traverse through all of the directories seeing and being able to access home (all cPanel accounts), root, usr, lib, etc.

Of course I have no intention of using that path for what I am doing - but this to me is a serious risk as anyone who has accounts on my VPS server could potentially use a similar script and have full access to my VPS root (accidentally or on purpose). Is there some setting that I am missing or need to change in my Apache settings to stop this from happening?

I presumed up until today, that only I can access my VPS Root and only access it with SSH using something like WinSCP or Putty - - - and yet low and behold I have been able to access it completely through a simple filemanager script that I wrote and placed in a cPanel account of one of my hosting clients. Does that make sense? The VPS that I have is unmanaged and the company offers no help when it comes to Apache configuration (if that is my issue) or other server software setup.

I have attempted all of the normal security features like making sure Fileprotect is enabled and in "Security Center" I have clicked on "Enable php open_basedir Protection." as well as several others that I have set previously.
wackter is offline
Reply With Quote
View Public Profile
 
 
Register now for full access!
Old 07-07-2010, 06:39 AM Re: possible VPS security issue
chrishirst's Avatar
Missing! presumed drunk.

Posts: 42,390
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
Depends on the user that the site is running under and the level of access that has.
__________________
Chris. ->>
Please login or register to view this content. Registration is FREE
<<-

A foolish consistency is the hobgoblin of little minds
Thought for today:- Is SEO the only industry where all the cowboys are Indians?
chrishirst is online now
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 07-07-2010, 06:44 AM Re: possible VPS security issue
Junior Talker

Posts: 2
Trades: 0
Quote:
Originally Posted by chrishirst View Post
Depends on the user that the site is running under and the level of access that has.
This is my VPS server where I have created a cPanel hosting account for my client and am logged in with his cPanel/FTP credentials for working on the site. When I run the Filemanager script from his website backend - with the directory set to "/" - - - I end up with full access to VPS root directory and all subdirectories. I logged out of WHM just to make sure that there wasn't something going on with me being logged in while I was working on the site in another browser window. Thanks for taking the time to help out.
wackter is offline
Reply With Quote
View Public Profile
 
Old 07-07-2010, 06:53 AM Re: possible VPS security issue
chrishirst's Avatar
Missing! presumed drunk.

Posts: 42,390
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
Sure, but what access does the cpanel user have?

Is that limited to the "home" directory for that one site?
__________________
Chris. ->>
Please login or register to view this content. Registration is FREE
<<-

A foolish consistency is the hobgoblin of little minds
Thought for today:- Is SEO the only industry where all the cowboys are Indians?
chrishirst is online now
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Reply     « Reply to possible VPS security issue
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.13488 seconds with 12 queries