ispCP ω Security Announcement

13 views
Skip to first unread message

Benedikt Heintel

unread,
Aug 29, 2010, 11:22:09 AM8/29/10
to ispcp-a...@googlegroups.com
Dear Readers,

today another critical security issue has been found. All ispCP Omega versions are effected.
It is possible to use the ispCP Client Backup Manager to restore forged backups and - in worst case - gain control over the server system.

We strongly recommend to fix the described security issue by disabling the backup restore routine. For this open the ispcp-dmn-mngr in /var/www/ispcp/engine/ and search for

    sub dmn_restore_data {

add

    exit 1;

directly in the next line.

We try to deliver a patch as fast as possible. You can follow the status in ticket: http://isp-control.net/ispcp/ticket/2440

Best regards
Benedikt Heintel

Project Manager

Benedikt Heintel

unread,
Aug 30, 2010, 6:47:40 PM8/30/10
to ispcp-a...@googlegroups.com
Dear Readers,

We have fixed the ispCP security issue discovered this week. For your
convenience we are releasing a patch against ispCP Omega 1.0.6 and will
also work with version 1.0.5.

It is strongly advised that you apply the attached patch. Remember to
delete the "exit 1;" command after "sub dmn_restore_data {".

After the patch has been applied successfully, run the backup manager to
change the permission of all backup folders and files to read only for
all users except the root user. To run the backup manager type the
following command in your server command line:

/var/www/ispcp/engine/backup/ispcp-backup-all yes

Please visit http://isp-control.net/ispcp/ticket/2440 for more information.

Kind Regards
Benedikt Heintel

Project Manager

security-2440.patch
Reply all
Reply to author
Forward
0 new messages