This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Asking about virtualhost home dir security
#1
Asking about virtualhost home dir security
Hey everyone, I just installed Sentora into my VPS for 3 days. But I see permission of everything in /var/sentora/hostdata/ are also set to 777. Isn't this a security risk? [b]Doesn't that mean anyone can write to my home dir?[/b]

[b]I don't know how to Sentora secure that folder with permission set to 777. Plz give me an information, thank you![/b]


Attached Files Thumbnail(s)
   
Reply
Thanks given by:
#2
RE: Asking about virtualhost home dir security
No this is not the case try using PHP to list folders outside the server root, it won't work.

We are using SUHOSIN to sandbox the webserver, so you should never disable it.

M B
No support using PM (Auto adding to IGNORE list!), use the forum. 
How to ask
Freelance AWS Certified Architect & SysOps// DevOps

10$ free to start your VPS
Reply
Thanks given by:
#3
RE: Asking about virtualhost home dir security
You can change the permissions to your liking,  but Sentora uses virtual users and each account is 'sandboxed' or locked down using suhosin and openbase_dir restrictions. If you disable either one of these server-wide or domain specific, you can open up your server to possible attacks.
-TGates - Project Council

SEARCH the Forums or read the DOCUMENTATION before posting!
Support Sentora and Donate: HERE

Find my support or modules useful? Donate to TGates HERE
Developers and code testers needed!
Contact TGates for more information
Reply
Thanks given by:
#4
RE: Asking about virtualhost home dir security
The settings do not allow access to mention folder.
Stay calm.
Reply
Thanks given by:
#5
RE: Asking about virtualhost home dir security
We use suhosin to enforce open_basedir

http://php.net/manual/en/ini.core.php#ini.open-basedir
No support using PM (Auto adding to IGNORE list!), use the forum. 
How to ask
Freelance AWS Certified Architect & SysOps// DevOps

10$ free to start your VPS
Reply
Thanks given by: Cantalupo


Possibly Related Threads…
Thread Author Replies Views Last Post
Security issue urgent johnnyp 7 12 ,668 02-27-2020, 06:19 PM
Last Post: johnnyp
SO MANY SECURITY ISSUES!! Sentora needs serious updates! aaronlroberts 9 19 ,574 11-24-2018, 01:48 AM
Last Post: siulian
ONLY home page working ! RobotMarketer 6 14 ,173 12-04-2017, 07:27 PM
Last Post: varun.naharia

Forum Jump:


Users browsing this thread: 1 Guest(s)