Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


cPanel Symlink Race Attack
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

cPanel Symlink Race Attack

Hello,

Currently I have one VPS to be used for cpanel share hosting account. The setting was using apache PHP with suPHP installed. Also AllowSymlink is allowed on Apache setting. Around 2 weeks ago my server got hacked by this sysmlink race attack...

Then I installed the mod_ruid2 on Apache.. but seems this mod_ruid2 ruin some of my email and php application.. also the server load seems a bit more high. As of now, I'm reverting back to my previous setting.

I read on some article, we can just disable the FollowSymlink options to prevent this attack. Is that right? But then some .htaccess setting may broke, right?

Any solution for this symlink problem?

Thanks...

Comments

Sign In or Register to comment.