Help - Search - Members - Calendar
Full Version: insecure apache setup? / critical bug in phpMyAdmin?
The Planet Forums > Control Panels > cPanel/WHM
jcaldera
As I was checking WHM today, it shows me this:

QUOTE
Security There are no known security problems with the build of cPanel you are using!  

You are running an insecure apache setup. You should run /scripts/easyapache or if you are running cPanel 7.1.9 or later (click here) to upgrade to a newer version as soon as possible to avoid your system being compromised.  


Anyone have an idea what this message means? I see the apache core latest version (v1.3.31) is the same as the installed version. Kinda confused here.

Secondly, is anyone aware of this and how we can fix this via WHM?

http://www.infoworld.com/article/04/10/14/...mysqlbug_1.html

"Users of the increasingly popular, open-source MySQL database may be at risk from remote attacks due to a bug in phpMyAdmin, a widely used Web-based MySQL administration tool. On Wednesday the phpMyAdmin project warned of a bug in the way the tool's MIME-based transformation system handles "external" transformations. Attackers could exploit the hole to execute arbitrary commands on a Web server with the privileges of the server's user, the project said in a statement."
AeroStar
you need to secure your apache by running /scripts/easyapche i recommend getting someone to do this for you if your not sure how to configure apache. As far as phpMyAdmin it should be secure under the cpanel setup.
~Tim
jcaldera
Yes, I've done that before and fixed that issue not too long ago. I was just wondering how I can find out what specificially in apache was insecure.

Thanks your reply....
ranger
What version of cPanel were you running?
eth00
If you scroll down a little farther it had a table which detailed everything about apache and one or more things had a lock. Recently php 4.3.9 became the stable from 4.3.8 which if I had to guess was your problem.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.