netenberg.com
July 30, 2010, 01:54:12 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News:
 
   Home   Help Search Login Register  
Pages: [1] 2 3 ... 5   Go Down
  Print  
Author Topic: possible exploit risk  (Read 39798 times)
scollins
Newbie
*
Posts: 5


« on: October 06, 2005, 10:34:11 AM »

I just found an eggdrop process on one of our machines running from:

/var/netenberg/fantastico_de_luxe/master_files/Zen_Cart/cache/

I'm noticing several dirs chmod'd to 777 in /var/netenberg/fantastico_de_luxe/master_files/

Is this totally neccessary? What a huge risk this is...
Logged
Mahendra
Administrator
Maestro
*****
Posts: 1921



« Reply #1 on: October 06, 2005, 11:32:57 AM »

We are aware of this (as it has been discussed a lot of times on the forum).

We have also prepared a strategy to overcome this potential problem. though we are yet to implement it.
Logged
scollins
Newbie
*
Posts: 5


« Reply #2 on: October 06, 2005, 01:23:05 PM »

Is it safe then to chmod them to something safer? Or are these 777 for reasons needed for the installs to work proper?
Logged
Mahendra
Administrator
Maestro
*****
Posts: 1921



« Reply #3 on: October 06, 2005, 01:33:27 PM »

No. The permissions pre-set by Fantastico De Luxe are absolutely essential to the proper working of the installed scripts.
Logged
bananaboy
Newbie
*
Posts: 3


« Reply #4 on: October 07, 2005, 06:32:13 AM »

It looks like it's installed under CubeCart directory too. Lucky our programmer made a custom script that notifies us when there's any unknown processes running and automatically emails us and kills it.

Mahendra mentioned it was posted several times on other threads but when I did a search for "eggdrop", I just found this one. Where are the other threads about this?

--------------
20678 eggdrop
lrwxrwxrwx    1 nobody   nobody          0 Oct  6 21:09 /proc/20678/exe -> /var/netenberg/fantastico_de_luxe/master_files/CubeCart/pear/tmp/pri/matahati/eggdrop-1.6.12 (deleted)
./eggdrop
Logged
scollins
Newbie
*
Posts: 5


« Reply #5 on: October 07, 2005, 06:46:56 AM »

There are a few other threads about the 777 permissions. Search for 777 and you should find them. Looks like they've been aware of this for some time now. I hope it gets fixed soon. What a pain in my arse. We have over 1000 servers running fantastico.
Logged
aussie
First Violin
*****
Posts: 166


« Reply #6 on: October 07, 2005, 08:09:42 AM »

Quote from: "scollins"
There are a few other threads about the 777 permissions. Search for 777 and you should find them. Looks like they've been aware of this for some time now. I hope it gets fixed soon. What a pain in my arse. We have over 1000 servers running fantastico.


1,000 server? ye right!
Logged
scollins
Newbie
*
Posts: 5


« Reply #7 on: October 07, 2005, 08:16:19 AM »

Quote from: "aussie"

1,000 server? ye right!


1492 active licenses to be exact. And that number grows every day.
Logged
aussie
First Violin
*****
Posts: 166


« Reply #8 on: October 07, 2005, 08:20:43 AM »

Quote from: "scollins"
Quote from: "aussie"

1,000 server? ye right!


1492 active licenses to be exact. And that number grows every day.


Ah ha! so your making over 1mil a year? I have a friend who has 200 servers. His income by the end of this year will be over 750k. Now thats on 200 servers. So you have 7x what he has so you must be making 5.25 Mil a year. Hmm. Really?
Logged
scollins
Newbie
*
Posts: 5


« Reply #9 on: October 07, 2005, 08:25:06 AM »

Quote from: "aussie"

Ah ha! so your making over 1mil a year? I have a friend who has 200 servers. His income by the end of this year will be over 750k. Now thats on 200 servers. So you have 7x what he has so you must be making 5.25 Mil a year. Hmm. Really?


This thread is not about our business, it is about the severity of this permissions issue. I'm not here to play games so go find a partner someplace else.
Logged
aussie
First Violin
*****
Posts: 166


« Reply #10 on: October 07, 2005, 08:33:01 AM »

Quote from: "scollins"
Quote from: "aussie"

Ah ha! so your making over 1mil a year? I have a friend who has 200 servers. His income by the end of this year will be over 750k. Now thats on 200 servers. So you have 7x what he has so you must be making 5.25 Mil a year. Hmm. Really?


This thread is not about our business, it is about the severity of this permissions issue. I'm not here to play games so go find a partner someplace else.


Well you bought it up. If you want to image that you have 1400 servers then good on you. I doubt you do but you dont have to bullshit either.
Logged
aussie
First Violin
*****
Posts: 166


« Reply #11 on: October 07, 2005, 08:34:39 AM »

Quote from: "scollins"
I just found an eggdrop process on one of our machines running from:

/var/netenberg/fantastico_de_luxe/master_files/Zen_Cart/cache/

I'm noticing several dirs chmod'd to 777 in /var/netenberg/fantastico_de_luxe/master_files/

Is this totally neccessary? What a huge risk this is...


If you were running phpseuxec this would not be a problem. All directories are chmod 755.
Logged
aussie
First Violin
*****
Posts: 166


« Reply #12 on: October 07, 2005, 08:39:38 AM »

Quote from: "aussie"
Quote from: "scollins"
I just found an eggdrop process on one of our machines running from:

/var/netenberg/fantastico_de_luxe/master_files/Zen_Cart/cache/

I'm noticing several dirs chmod'd to 777 in /var/netenberg/fantastico_de_luxe/master_files/

Is this totally neccessary? What a huge risk this is...


If you were running phpseuxec this would not be a problem. All directories are chmod 755 with the following exceptions;

Coppermine_Photo_Gallery
Moodle
PHProjekt
Siteframe
Soholaunch_Pro_Edition
ViPER_Guestbook

Maybe Netenburg can explain why these directories need to be 0777 while all the others are 0755? Under phpsuexec they should be 0755.
Logged
Mahendra
Administrator
Maestro
*****
Posts: 1921



« Reply #13 on: October 07, 2005, 08:55:04 AM »

Quote from: "aussie"
Maybe Netenburg can explain why these directories need to be 0777 while all the others are 0755? Under phpsuexec they should be 0755.


Hi,

Unfortunately this is a limitation of the internal design of Fantastico De Luxe. As I said earlier, we are trying to eliminate this at the source itself. Kindly co-operate with us for a few more releases till we put an end to this.

But, upon installation (in phpsuexec servers), we automatically change the permissions on all files to 755 (to overcome Internal Server Error).
Logged
aussie
First Violin
*****
Posts: 166


« Reply #14 on: October 07, 2005, 08:59:13 AM »

Quote from: "Mahendra"

But, upon installation (in phpsuexec servers), we automatically change the permissions on all files to 755 (to overcome Internal Server Error).


NO YOU DONT! Under phpsuexec on all my boxes the apps listed above have a directory permission of 0777. Maybe you should check your installer, updater. Sorry to burst your bubble.  Tongue
Logged
Pages: [1] 2 3 ... 5   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!