Giter VIP home page Giter VIP logo

addon_securityadvisor's People

Contributors

annes449 avatar atoomic avatar bdraco avatar bk2204 avatar colmelvin avatar cpanel-jared avatar cpaneljamyn avatar cpanelrikus avatar cpdans avatar davelcpanelnet avatar demasu avatar escherlat avatar example123 avatar jamyn avatar sporks5000 avatar toddr avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

addon_securityadvisor's Issues

Jail Shell detection seems broken in 11.60

Steps to reproduce:

Install the latest EDGE build.
Create an account.
Set the shell to normal shell via WHM >> Account Functions >> Manage Shell Access.
Go to WHM >> Security Center >> Security Advisor.
Notice that there is no warning about un-jailed users.

Suggestions: cPAddons

Just documenting suggestions submitted by others so we don't lose them.

  • cPAddons (I've been playing with these)
  • ERROR: installed into user's docroots but not installed in WHM
  • ERROR: deprecated cPAddons installed in a user's docroots.
  • ERROR: version installed in a user's docroot does not match current
    WHM version
  • ERROR: WHM version of cPAddon is not latest version on httpupdate mirrors

Suggestions: UI

  • Switch to static interface that displays the result of
    the last scan,
  • Add a button to perform a scan and uses comet to load the
    scan results into the interface. The way it's organized now you have to
    avoid doing any time-consuming checks since the interface wont render
    until they're all complete.
  • Add the ability to sort result types so we're not left with one large page containing hundreds of results. (sort by type, exclude "pass" results, etc)

Suggestions: WHM Plugins

Just documenting suggestions submitted by others so we don't lose them.

  • ERROR: Any installed that are out of date
  • ERROR: Any deprecated WHM plugins are still installed.

Suggestions: EasyApache

Just documenting suggestions submitted by others so we don't lose them.

  • ERROR: Tomcat is installed (current version is EOL, runs as shared user)
  • ERROR: Mono is installed (current version is EOL, runs as shared user?)
  • WARN: Mod_security not installed (warning since the hosting provider
    may have a separate WAF)
  • ERROR: Any caching PHP extensions installed (allow various kinds of
    cache poisoning to take over other sites depending on the configuration.)
  • ERROR: PHP4 installed on the system (EOL, numerous CVEs)
  • ERROR: PHP 5.[012] installed on the system (EOL, numerous CVEs)
  • ERROR: PHP 5.3 or 5.4 installed on the system with any version other
    than the latest.

DONE - ERROR: Apache 1 installed (EOL, CVEs)
DONE - ERROR: Apache 2.0 installed (Near EOL, upstream support is spotty)

  • ERROR: Apache 2.2/2.4 is installed other than the latest version

Suggestions: Misc

Just documenting suggestions submitted by others so we don't lose them.

  • ERROR: entropychat is enabled (need to open fogbugz cases to document
    the problems here)
  • ERROR: scgi-bin wrapper is in use (haven't ever heard a good reason
    why this is even in the product.)
  • WARN: hooks of any type are installed (standardized, pre/post scripts,
    etc)

Suggestions: MySQL

Just documenting suggestions submitted by others so we don't lose them.

  • ERROR: MySQL configured to listen for remote connections and not
    configured to use SSL
  • ERROR: MySQL grants allowing remote users do not require SSL
  • WARN: MySQL accepting remote connections with SSL configured

Suggestions: Mail

Just documenting suggestions submitted by others so we don't lose them.

  • something that reviews settings that may affect incoming and outgoing spam prevention and detection such as header additions and whether it's setup optimally. Especially the latter, as the headers of outgoing messages are often how I've caught account level AND root level compromises.

Suggestions: SSL

Just documenting suggestions submitted by others so we don't lose them.

  • ERROR: WHM/cPanel/Webmail/webdav not configured to require SSL
  • ERROR: POP/IMAP/SMTP not configured to require SSL prior to authentication
  • ERROR: FTP enabled and does not REQUIRE ssl

Suggestions: Updates

Just documenting suggestions submitted by others so we don't lose them.

  • WARN: cpsources.conf is not tracking httpupdate.cpanel.net
  • ERROR: cPanel updates are tracking 11.30
  • ERROR: cPanel updates are tracking a 4 digit version number
  • ERROR: cPanel updates set to manual and installed version is out of date
  • WARN: cPanel updates set to manual and installed version is up to date
  • WARN: cPanel updates are tracking a 2 digit tier instead of a named tier
  • WARN: custom versions installed for any cPanel managed RPMs.

Suggestions: OS

Just documenting suggestions submitted by others so we don't lose them.

  • ERROR: Latest kernel updates from CentOS/RedHat/CloudLinux are not
    installed.
  • ERROR: Running kernel is not the same as the newest kernel on the system.
  • ERROR: OS Updates are disabled/manual
  • ERROR: Other OS Updates are available
  • ERROR: OS Updates are tracking a specific point release rather than
    the major release.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.