Web Hosting Talk







View Full Version : Security Warning - Interland users


Runboy
03-14-2001, 04:38 AM
Major security breach on Interlands servers:

I checked my shared account at Interland.net and was surpriced to discover that you can access all files on the server with the File System Object (FSO). This is a major security breach, since that gives me access to all the files on 200 other accounts and I can easily get their usernames & passwords for their databases etc. It doesn't help much that they allow any IP adress to access their MS-SQL Servers, so if I or any other wanted to we could easily get full access to other peoples data. (PS - I contacted them about the issue and initially it took them 1½ week to even answer my email and when they finally did, they just said they would solve the problem sometime in the future.)

So Interland users. Everybody on you server has full access to your files ! ! !

AlaskanWolf
03-14-2001, 05:11 AM
this is pretty much possible on any linux based server

Runboy
03-14-2001, 08:42 PM
It is an NT Server and it is fairly easy to set it up so the users only have access to their own webaccount.

Regards John Raahauge

energy
03-14-2001, 10:31 PM
It's a problem on many Win NT servers, Interland has been having this problem for at least a year.

Runboy
03-15-2001, 05:00 PM
It is weird they don't fix the problem. They just have to make independent IUSR_XX for each account, instead of going with the default anonymous account.
It is totally unsat for any webhost to accept such a security breach. Somebody ought to inform all their ecommerce users about the problem.

klisis
03-15-2001, 05:45 PM
I am hearing many bad things about interland recently...

nisus
03-17-2001, 12:27 PM
I wish they'd stop sending me dozens of promo's in the mail!