Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 13 of 13

This is a discussion on Pretty huge security hole.. in the Shared & Semi-Dedicated forum
open_basedir isn't set, and you can't set it through .htaccess. If anyone plans on giving a friend a subdomain or something, they have access to ...

  1. #1
    JPC Member
    Join Date
    Jan 2004
    Posts
    5

    Pretty huge security hole..

    open_basedir isn't set, and you can't set it through .htaccess.

    If anyone plans on giving a friend a subdomain or something, they have access to all of their files.

  2. #2
    Tim
    Tim is offline
    Loyal Client
    Join Date
    Mar 2002
    Location
    Georgia, USA
    Posts
    146
    If you create an FTP account for your friend, I believe they would have access to only that directory.


    Tim

  3. #3
    JPC Member
    Join Date
    Jan 2004
    Posts
    5
    PHP functions like opendir and fopen can be used.

  4. #4
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    If you need to restrict access like that, contact support and have them disable it in the <VirtualHost> directive of the Apache conf for your site. Personally, if it was enabled globablly on my server, it would break my site, as I store many parts of my site (and my subdomains) outside of public_html for security purposes. Having open_basedir unset isn't a "huge security hole" for the average user--its actually much more secure to not have it set for sites such as my own.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  5. #5
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Originally posted by jason
    Personally, if it was enabled globablly on my server, it would break my site...
    OMG! Can you imagine, no GD, no fonts, no nothing...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  6. #6
    JPC Member
    Join Date
    Jan 2004
    Posts
    5
    Having open_basedir unset isn't a "huge security hole" for the average user--its actually much more secure to not have it set for sites such as my own.
    Pardon my terrible wording.

    If you need to restrict access like that, contact support and have them disable it in the <VirtualHost> directive of the Apache conf for your site.
    Um, where would I find this?

  7. #7
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    Originally posted by jaquatak
    Um, where would I find this?
    Support will need to set it up for you in for each of the subdomains you wish to restrict. Just open a support ticket and explain what you want to do and they should be able to do it without a problem. Its not something you'll be able to set up on your own.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  8. #8
    JPC Member
    Join Date
    Jan 2004
    Posts
    5
    I assume you open a ticket somewhere in here:

    https://secure.jaguarpc.com/jaguarpc/clients/

    It won't let me log in there.

  9. #9
    Old Hillbilly Connie's Avatar
    Join Date
    Sep 2001
    Location
    Hills of Missouri
    Posts
    2,646
    Originally posted by jaquatak
    I assume you open a ticket somewhere in here:

    https://secure.jaguarpc.com/jaguarpc/clients/

    It won't let me log in there.
    Try this:

    http://www.jaguarpc.com/?loc=default

    The page your pointing to is an old page. I wouldn't think it would make
    a difference. I could sign in from that page but who knows.

    Forum Moderators - Jag Staff

    Spam Whackers Blog - Dedicated to fighting Spam and providing General SEO Tips
    Organize your Kitchen or purchase Kitchen Accessories at Condells
    Ihelpyou Forum - Dedicated to "Best Practices" SEO

  10. #10
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    Your sign in is probably your full domain name and whatever your original password was when your account was set up, unless you've been here a while, in which case your site's login name and the client section login name may be the same. Some people have reported having to capitalize the first letter of the username as well.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  11. #11
    JPC Member
    Join Date
    Jan 2004
    Posts
    5
    Neither work. And just conveniently, I didn't register the account myself, so I don't have the info for the lost pass thing. Ah, well. I'll just have to wait until the guy who registered the account gets on.

    By the way, is five months considered a while?

  12. #12
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Heh! This is making less sense all the time...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  13. #13
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    Originally posted by jaquatak
    By the way, is five months considered a while?
    I'm not sure when they started using domain names instead of usernames for the client section, but I think it was longer than 5 months ago. When the client section first went on line--I think it was about two years ago--they issued every then current client an account using the same usernames and passwords as we had for our sites. Then suddenly one day they switched to domain names.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •