Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· PHP 5.2.17-12 for CentOS 5
· Apple removes iPhones, iPads from German online store due to injunction
· New Apple iMac touchscreen tech outed in new patent
· CSF 5.45 released
· CompatDB Updates 02/03/12
· Daily Reviews Summary 02/03/12
· Nokia Lumia 900 up for pre-order at Microsoft Store, $25 down puts you in line
· Install Airtime (Free radio automation software) in Ubuntu
· PHP 5.3.10 for Debian
· Microsoft: Windows Phone 8 To Use NT Kernel

Upcoming News
· Five Years With Blu-ray - Part Two
· Galaxy MDT GeForce GT 520 Graphics Card Review
· SSD NEWS: Kingston SSDNow V+ 200 120GB SATA III SSD (Upgrade Bundle Kit) Review
· Corsair Force Series 3 and Force Series GT SSD Full Review
· Final Fantasy XIII-2 (XBOX 360) Review @ HardwareHeaven.com
· Changes to HEXUS accounts - important information
· AC Ryan Veolo @ techPowerUp
· Enermax ETS-T40-VD CPU Cooler Review @ eTeknix.com
· Ubuntu 12.04 ARM Performance Becomes Very Compelling
· Antec Three Hundred Two Case Review @ Hardware Secrets

Linux Compatibility
· XPS L502X
· Slim Portable DVD Writer GP10
· AverTV Volar Green HD
· Dell Latitude E6420
· Canon CanoScan FB 636U
· Logitech QuickCam Pro 4000
· GeForce 7300 GT
· Umax Astra 4500 USB Scanner
· Photosmart Pro B9180
· kingston DataTraveler DTI/16GB

New Forum Topics
· Code: Bad EIP Value
by: megatouchguy
on: 2012-01-28 06:27
0 replies, 239 views

· XP Pro crashes on start up
by: javien
on: 2012-01-17 12:38
6 replies, 1943 views

· Lan Wireless Access To Shared Folders Problem
by: MinusZero
on: 2012-01-09 06:45
2 replies, 2119 views

· Motherboard glitch
by: danleff
on: 2012-01-08 12:03
3 replies, 576 views

· Problem with Wireless causing Router Resets
by: msittig
on: 2012-01-06 16:58
3 replies, 12675 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » July 2010 » ispCP Omega 1.0.5 Security Announcement II

ispCP Omega 1.0.5 Security Announcement II

Posted by Philipp Esselbach on: 07/30/2010 11:02 AM [ Print | 0 comment(s) ]

Another small vulnerability has been discovered in ispCP Omega 1.0.5 while running in DEBUG mode




Today we discovered another fault, this time in the ispCP Omega Engine if DEBUG is set to 1 in ispcp.conf. (System default is 0.)

On Database backup the password for the ispCP database user is shown and logged in clear text, while logs are world readable. It is recommended to fix this bug by either set DEBUG to 0 or use the patch attached to ticket 2411.

An Identical security hole was discovered today in these scripts:

engine/backup/ispcp-backup-all
engine/backup/ispcp-backup-ispcp

The patch attached to the ticket #2411 was updated today.

Also, it's recommended to remove all the /var/log/ispcp/* log after fixing this security hole by setting debug mode to 0, or by applying the patch. For versions prior to ispCP 1.0.5, it's strongly recommended to migrate and to apply the patch.

Note: For the last script, it's really more important because this time, it's the main SQL account login (eg. SQL root account) credentials that is stored in cleartext.

We apologize for any inconvenience caused.


ispCP Omega 1.0.5 Security Announcement II


Bookmark and Share

Related Stories

07/25/2010 04:46 PM: ispCP Omega 1.0.5 Security Announcement by Philipp Esselbach
A security patch has been released for ispCP Omega 1.0.5...

03/01/2010 10:04 AM: ispCP Omega 1.0.4 Released by Philipp Esselbach
ispCP Omega 1.0.4 has been released...

12/20/2009 10:38 AM: ispCP Omega 1.0.3 Released by Philipp Esselbach
ispCP Omega 1.0.3 has been released...

02/26/2009 07:35 PM: ispCP Omega v1.0.0 Stable released by Philipp Esselbach
ispCP Omega v1.0.0 Stable has been released...

08/06/2008 10:47 AM: ispCP Omega 1.0.0 RC6 released by Philipp Esselbach
ispCP Omega 1.0.0 RC6 has been released...

03/17/2008 10:08 AM: ispCP Omega 1.0.0 RC4 by Philipp Esselbach
ispCP Omega 1.0.0 RC4 has been released...


« java-1.4.2-ibm security update · CompatDB Updates 07/30/10 »

Linux Compatible » News » July 2010 » ispCP Omega 1.0.5 Security Announcement II
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2011 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition