Security Audit [ Linux ] [ 90% shared hosts vulnerable ] [Read!]

Discussion in 'Services' started by torhost, Feb 16, 2008.

  1. #1
    Hey all,

    Is your hosting website hosted on the same server as the shared hosting accounts you sell? Then you might be vulnerable!

    Over 90% of hosting companies suffer from this simple vulnerability that can give any malicious user full on root access to the server.

    And by 90% of hosting companies, I really do mean 90%.

    There is an extremely easy fix for this, one command via ssh and it's fixed.

    If you're interested please PM me - All I will require for my audit is 2 minutes and a temporary shared hosting account you can provide me with.

    I will audit the first three people for free in hopes of obtaining feedback as once I explain to you what the vulnerability is and how it works, you will be in shock.

    Again, Please PM me if you're interested! The audit shouldn't take longer then 2 minutes!

    Again, first 3 free
     
    torhost, Feb 16, 2008 IP
  2. cpmfast

    cpmfast Peon

    Messages:
    424
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    As Seller:
    100% - 0
    As Buyer:
    100% - 0
    #2
    I am interested, what is involved?
     
    cpmfast, Feb 16, 2008 IP
  3. torhost

    torhost Banned

    Messages:
    348
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    As Seller:
    100% - 0
    As Buyer:
    100% - 0
    #3
    Well this service is mainly aimed at people whom own their own servers / web hosting companies, but basically the only thing that is involved is

    1. Create for me a temporary shared hosting account
    2. Give me 60 seconds
    3. Fix Vulnerability if there is one


    whole process shouldn't take more then 2 minutes
     
    torhost, Feb 16, 2008 IP
  4. Rub3X

    Rub3X Well-Known Member

    Messages:
    1,902
    Likes Received:
    75
    Best Answers:
    0
    Trophy Points:
    135
    As Seller:
    100% - 0
    As Buyer:
    100% - 0
    #4
    Why not just tell three members, one being me what the vulnerability is. I have used Linux as both a server, desktop, and router. I'm pretty sure I'd be able to review this ;)
     
    Rub3X, Feb 16, 2008 IP
  5. torhost

    torhost Banned

    Messages:
    348
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    As Seller:
    100% - 0
    As Buyer:
    100% - 0
    #5
    It actually isn't a vulnerability in linux itself, in theory it isn't a vulnerability but since it allows malicious users to gain root access, and can be avoided by a simple command, I consider it one.

    I promise anyone that uses this service will be pretty amazed at what a hacker "could" have done
     
    torhost, Feb 16, 2008 IP
  6. torhost

    torhost Banned

    Messages:
    348
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    As Seller:
    100% - 0
    As Buyer:
    100% - 0
    #6
    Because the vulnerability only exists on sites using linux OS
    and it isn't cpanel or php, it's just slipup in configuration


    Many sites may honestly "think" they are secure with their "security team" and be outright cocky about it, but trust me...

    Dreamhost
    Siteground
    Lunarpages

    one customer has the ability to view all the other customer's FTP contents, MySQL data, etc...
     
    torhost, Feb 16, 2008 IP
  7. Camay123

    Camay123 Well-Known Member

    Messages:
    3,423
    Likes Received:
    86
    Best Answers:
    0
    Trophy Points:
    160
    As Seller:
    100% - 0
    As Buyer:
    100% - 13
    #7
    Same here.
     
    Camay123, Feb 16, 2008 IP