This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Security issue urgent
#6
RE: Security issue urgent
(02-15-2020, 12:24 AM)Ron-e Wrote: issn't the shell_exec function disabled by default tru suhosin?
So if you can run shell_exec you costumed Sentora and you compromised the security of Sentora yourself or suhosin is broken.


I got this message:

When executing:
Code:
<?php
ini_set('display_errors', 1);
ini_set('display_startup_errors', 1);
error_reporting(E_ALL);
echo shell_exec("cat /etc/sentora/panel/cnf/db.php");
?>

Well it seems that i did my self, but shouldn't the admin be able to just enable some commands to some users?

I believe that some commands are crucial for web development and exec is one of them. 

Maybe locking php interpreter inside a user virtual home would be a solution to that. 

Anyway as stated i do not use the cpanel for commercial use so i can't find any security issues by enabling some commands as i am the only one that has access to php but on the other hand i can think some situations were a simple code injection could be catastrophic. 

What is your opinion on that, am i safe with disabled suhosin as long as i am the only one with access to server? 

Thank you.
Thanks given by:


Messages In This Thread
Security issue urgent - by johnnyp - 02-12-2020, 05:23 PM
RE: Security issue urgent - by Jettaman - 02-13-2020, 02:52 AM
RE: Security issue urgent - by johnnyp - 02-13-2020, 05:06 PM
RE: Security issue urgent - by Ron-e - 02-15-2020, 12:24 AM
RE: Security issue urgent - by johnnyp - 02-17-2020, 05:08 PM
RE: Security issue urgent - by Me.B - 02-17-2020, 02:49 AM
RE: Security issue urgent - by Me.B - 02-24-2020, 04:46 AM
RE: Security issue urgent - by johnnyp - 02-27-2020, 06:19 PM

Possibly Related Threads…
Thread Author Replies Views Last Post
Old issue on Daily Backup iraqiboy90 24 112 ,637 12-26-2020, 12:48 PM
Last Post: conglynina
sub-domain issue kevwebbie 15 30 ,316 12-21-2018, 05:51 PM
Last Post: kevwebbie
Wordpress "Temp Folder Missing" Issue NickNeverSleeps 5 12 ,520 12-13-2018, 09:20 PM
Last Post: ngeluis@gmail.com

Forum Jump:


Users browsing this thread: 1 Guest(s)