Server Software and Configuration Services
New csf v2.81
Changes:
- Added exe:/usr/local/cpanel/cpdavd to csf.pignore
- Added option to disable refresh in WHM csf UI when viewing lfd.log
- Removed debug code that prevented IP blocking — oops
Changes:
Changes:
If you are finding chkservd restarting lfd, antirelayd, mailscanner or other monitored process then there’s a bug in the latest chkservd. cPanel have been informed via the EDGE users mailing list (just now). Whilst waiting for a fix, you have two options:1. Untick the monitored services that chkservd keeps restarting falsely in WHM > Service Monitor > under the Monitor list. The dowside of this is that those processes won’t be monitored if they fail. You will also need to tick them again once cPanel have fixed chkservd2. Apply the following modification yourself. The upside is that monitoring continues, the downside is that it’s unofficial and will be overwritten after a upcp upgrade:Edit /usr/local/cpanel/libexec/chkservd and go to line 369 and change it from:
An interesting report as been posted recently about the inherent dangers of allowing code to run under the same username as the apache process, i.e. nobody. This happens if you run PHP as a module, or CGI scripts without SUExec protection:http://seclists.org/bugtraq/2007/Jun/0250.htmlOf course, this is not anything new and the dangers have been known about for a long time. However the paper explains just how vulnerable you really are if you don’t protect your apache configuration from code being run within the context of its own user.Note that this affects both apache v1 and v2.Avoiding this issue is relatively simple:1. Enable SUExec (which is the default on cPanel installs)2. Enable PHPsuexec (or SuPHP), and understand the limitations that imposesLeaving your server without protection is inviting hackers to exploit your whole server including all your clients data, through a simple hole in one PHP script on one account on your server.An interesting take on this report is also discussed by the creator of mod_security:http://www.modsecurity.org/blog/archives/2007/06/apache_process.html
If you receive the following email on cPanel v11 and you’re running our MailScanner package or are not using the cPanel inbuilt SpamAssassin setup:
Changes:
Changes:
If you see a blank page in WHM for MSFE after upgrading from a previous version, upgrade to this release by following the instructions here:http://www.configserver.com/cp/msfeinstaller.html
Changes:
Changes:
Changes: