Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 6 of 6

This is a discussion on Is it normal for new accounts to be able to execute programs? in the VPS & Dedicated forum
I just got my VPS with WHM set up and I am doing some testing. When I create a new hosting account I can log ...

  1. #1
    Loyal Client Pawel Kowalski's Avatar
    Join Date
    Sep 2001
    Location
    Albuquerque NM
    Posts
    1,405

    Is it normal for new accounts to be able to execute programs?

    I just got my VPS with WHM set up and I am doing some testing. When I create a new hosting account I can log in to SSH using that account. When I am connected using SSH I am able to download programs using wget, change their permissions to executable and then actually execute them.

    Is this normal with any SSH access? If it is how can I actually block WHM from setting up a SSH account with each new web hosting account I add?

  2. #2
    Loyal Client
    Join Date
    Sep 2001
    Location
    Wichita, KS
    Posts
    1,647
    a VPS is an entire pretend server... that's how it's supposed to work, i think

  3. #3
    CTO JPC-Masood's Avatar
    Join Date
    Aug 2002
    Location
    Jaguar Servers
    Posts
    2,070
    In WHM, when you create account, you can choose not to give shell access. You can also turn it on/off from WHM

    Main >> Account Functions >> Manage Shell Access

    Shell access should only be provided to trusted party, like we do to you guys on the shared hosting

    Masood N. | Chief Technical Officer
    JaguarPC.com


    Helpful Links
    Knowledge Base | Network Status

  4. #4
    CTO JPC-Masood's Avatar
    Join Date
    Aug 2002
    Location
    Jaguar Servers
    Posts
    2,070
    Forgot to add, yes its normal for the user to be able to execute programs. It is a proper unix account. And by not giving shell access you are not protected. A single line of bad code can give remote shell access to any internet user (i.e. ability to run arbitrary code on the vps). So all accounts on your vps should be protected by following the security guidelines:

    Tips on Web Security

    Masood N. | Chief Technical Officer
    JaguarPC.com


    Helpful Links
    Knowledge Base | Network Status

  5. #5
    all about nothing! Frank Broughton's Avatar
    Join Date
    Jan 2006
    Posts
    2,158
    I believe you can also force all users to use jail shell in whm. Can't check for sure right now as my VPS is being migrated to Atlanta right now.

  6. #6
    CTO JPC-Masood's Avatar
    Join Date
    Aug 2002
    Location
    Jaguar Servers
    Posts
    2,070
    Jail only restricts a user from roaming around the server and reading files outside of their account, but will still allow to run programs or background scripts etc.

    Masood N. | Chief Technical Officer
    JaguarPC.com


    Helpful Links
    Knowledge Base | Network Status

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •