hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Software and Control Panels : Again about security hole in CP!
Reply

Hosting Software and Control Panels Software used in the web hosting industry. Topics include control panels, add-on software, setup scripts, etc.
Forum Jump

Again about security hole in CP!

Reply Post New Thread In Hosting Software and Control Panels Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 04-16-2001, 08:07 AM
bigAl bigAl is offline
Registered User
 
Join Date: Apr 2001
Posts: 29
Hi again, guys… why did you delete my last thread? Do you afraid of something?

I will repeat:
There’s a great (BIG) security hole in VDI’s CP3! You can get any file from any server running CP3.
More than that! I can get a root access on ANY server running CP3! (But this host must provide a demo access to CP).

I can tell the VDI’s support about the hole, and about how to use it, but it will cost some $$$. Or i can hack a server... if you whant... $$$ - and server's yours.
As a demo, I can create a new user with ssh access on any server running CP.

Mail me, guys… or use the ICQ (profile) to contact me.

PS: To ask 250 per month, first think about the security… guys…

Reply With Quote


Sponsored Links
  #2  
Old 04-16-2001, 08:29 AM
Starhost Starhost is offline
Web Hosting Evangelist
 
Join Date: Nov 2000
Posts: 486
HHahhahaha, you are so fun! Why should we pay ya? Are you that poor. And if there were a real security hole, there would already be some servers hacked.

And when there are servers hacked with the cp, we now who did it you fool.

Reply With Quote
  #3  
Old 04-16-2001, 08:40 AM
bigAl bigAl is offline
Registered User
 
Join Date: Apr 2001
Posts: 29
you won't know who did that

to others: if you own a hosting company, and whant to hack another hosting company (i bet you could gues what for) just mail me

Reply With Quote
Sponsored Links
  #4  
Old 04-16-2001, 08:45 AM
cperciva cperciva is offline
Retired Moderator
 
Join Date: Jan 2001
Posts: 2,603
Quote:
Originally posted by bigAl
to others: if you own a hosting company, and whant to hack another hosting company (i bet you could gues what for) just mail me
Mods, do you want to ban this guy? Call me old fashioned, but advertising felonous services here seems a bit rediculous, even if it is probably done in jest.

Reply With Quote
  #5  
Old 04-16-2001, 09:04 AM
bigAl bigAl is offline
Registered User
 
Join Date: Apr 2001
Posts: 29
he scared?

I'm serious! There's a big hole. And you, guys should try to fix it. And you are trying to ban the man who CAN and WILL help you. cperciva, we should work together i think. You, as a service provider, MUST be interested! I can work for you to fix this hole! Try to understand - i'm NOT your opponent.

I can repeat:
When you what to get 250 per month - spent 2500 for the security.


Last edited by bigAl; 04-16-2001 at 09:12 AM.
Reply With Quote
  #6  
Old 04-16-2001, 09:07 AM
kunal kunal is offline
Web Hosting Master
 
Join Date: Aug 2000
Posts: 2,750
bigAl is right.. there is a hole.. and they are working on a fix for it..

__________________
The Php Support Desk
http://www.phpsupportdesk.com
Custom programming - kunal @ e-phoria.com
http://www.pingzine.com - Ping!Zine. the FREE, FRESH and EXCITING Web Hosting Magazine...

Reply With Quote
  #7  
Old 04-16-2001, 09:08 AM
Starhost Starhost is offline
Web Hosting Evangelist
 
Join Date: Nov 2000
Posts: 486
Alright Bigal, then hack the server where vdi's server is running on. You said you can do it, so prove it, I'll bet you can't lame poor fellow

Reply With Quote
  #8  
Old 04-16-2001, 09:12 AM
bigAl bigAl is offline
Registered User
 
Join Date: Apr 2001
Posts: 29
Quote:
Originally posted by Starhost
You said you can do it, so prove it, I'll bet you can't lame poor fellow
I'll make a deface - i'll tell you when it will be ready.

Reply With Quote
  #9  
Old 04-16-2001, 09:59 AM
bigAl bigAl is offline
Registered User
 
Join Date: Apr 2001
Posts: 29
NOW,

i edited some page... be serious! thre's a hole!

site: http://canyonrimmall.com/
hosting: http://jaguarpc.com
demo: http://jaguarpc.com/demo.php

View the cource of the http://canyonrimmall.com/ page. There's a comment at the end of the page.

"<!--Test this page. Merlin. -->"

I tried not to do harm to anybody...

Now try this:
http://canyonrimmall.com/*****.cgi
No password heh?

Do you belive me now?


2 VDI:
Will we work together?


Last edited by bigAl; 04-16-2001 at 10:32 AM.
Reply With Quote
  #10  
Old 04-16-2001, 10:03 AM
bigAl bigAl is offline
Registered User
 
Join Date: Apr 2001
Posts: 29

Reply With Quote
  #11  
Old 04-16-2001, 10:10 AM
William William is offline
Shaping How Hosting is Done
 
Join Date: Sep 2000
Location: NY
Posts: 489
Thats not a cpanel script

What you have attempted to hack was a "Domain owner" issue.

They need to adjust thier own permmsions correctly.

Reply With Quote
  #12  
Old 04-16-2001, 10:14 AM
Chicken Chicken is offline
Web Hosting Master
 
Join Date: Jun 2000
Location: Southern California
Posts: 12,121
Quote:
Originally posted by bigAl
View the cource of the http://canyonrimmall.com/ page. There's a comment at the end of the page.

"<!--Test this page. Merlin. -->"

I tried not to do harm to anybody...

Now try this:
http://canyonrimmall.com/cgi-bin/admin/admin.cgi
No password heh?
Don't see that Merlin thing. The other is a cgi script that doesn't have a .htaccess file in the admin panel (not brilliant but not cracked). If I took the .htaccess file out of my phpmyadmin dir, you'd be able to access that too, but you can't since I have it in. I don't get what this is about.

__________________
HostHideout.com - Where professionals discuss web hosting.

• Chicken

Reply With Quote
  #13  
Old 04-16-2001, 10:22 AM
bigAl bigAl is offline
Registered User
 
Join Date: Apr 2001
Posts: 29
Re: Thats not a cpanel script

Quote:
Originally posted by William
What you have attempted to hack was a "Domain owner" issue.

They need to adjust thier own permmsions correctly.
i used a hole in cp.
It doesn't metter weather user sets the permisssins correctly - because i've edited the file, using USERS's access permissions! And user MUST be able to edit his own files. About LINKS script... it uses .htaccess file.

Reply With Quote
  #14  
Old 04-16-2001, 10:27 AM
bigAl bigAl is offline
Registered User
 
Join Date: Apr 2001
Posts: 29
Quote:
Originally posted by Chicken

Don't see that Merlin thing. The other is a cgi script that doesn't have a .htaccess file in the admin panel (not brilliant but not cracked). If I took the .htaccess file out of my phpmyadmin dir, you'd be able to access that too, but you can't since I have it in. I don't get what this is about.
OH! Sorry, i have made a rebuil from the LINKS admin's panel when adden a new link (http://canyonrimmall.com/Web_Services/).

LINKS script:
there WAS .htaccess file and there ISn't sucn file there now.

I will add the comment again.

Reply With Quote
  #15  
Old 04-16-2001, 10:30 AM
bigAl bigAl is offline
Registered User
 
Join Date: Apr 2001
Posts: 29
done.
the comment was added again.

2 VDI:
what do U think of it?

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Secure128 Launches IT Security Services, Names VP of IT Security Sales Web Hosting News 2012-07-13 12:51:15
Cloud Security Firm Dome9 Adds Group-Based Firewall Policy Management Function Web Hosting News 2012-01-25 12:41:56
Cloud Security Firm nCircle Joins Cloud Security Alliance Web Hosting News 2012-01-12 15:35:20
McAfee Report Finds Management Out of Touch with Data Center Security Web Hosting News 2011-10-03 17:33:23
Web Host Go Daddy Implements Trend Micro Deep Security Solution Web Hosting News 2011-08-17 16:21:53


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?