Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

Security discussion

General questions about VestaCP
Post Reply
  • Print view
Advanced search
27 posts
  • Previous
  • 1
  • 2
  • 3
  • Next
ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: Security discussion
  • Quote

Post by ScIT » Mon Oct 08, 2018 8:46 am

alexcy wrote: ↑
Mon Oct 08, 2018 8:34 am
Since you are somehow closer to the team than most of us, can we somehow get a word from Serghey?
I don't have any direct contact to Serghey, just beeing a mod here :-). But I know that he was contacted multiple times, but - as far as I know - he didn't respond.
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: Security discussion
  • Quote

Post by ScIT » Mon Oct 08, 2018 8:48 am

Spheerys wrote: ↑
Mon Oct 08, 2018 8:44 am
Thanks ScIT !
No promise - personally I don't want that vesta will die! I just checked the other control panel on the market and have to say, that vesta is the only one i want to use.
Top

alexcy
Posts: 256
Joined: Sun Jun 01, 2014 11:24 pm
Contact:
Contact alexcy
Website

Os: Ubuntu 15x
Web: nginx + php-fpm
Re: Security discussion
  • Quote

Post by alexcy » Mon Oct 08, 2018 8:50 am

Completely agree SCiT. VestaCP has no reliable alternatives.

Unfortunately I am not a developer myself. I can make minor changes/modifications but that's it.
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: Security discussion
  • Quote

Post by ScIT » Mon Oct 08, 2018 8:51 am

by the way: Also we tried to contact ctrlpac (thread opener), but he didnt respond to a pn from mehargags. Maybe he can try to contact me if he still has interrests to support vesta.
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: Security discussion
  • Quote

Post by ScIT » Mon Oct 08, 2018 8:55 am

alexcy wrote: ↑
Mon Oct 08, 2018 8:50 am
Completely agree SCiT. VestaCP has no reliable alternatives.

Unfortunately I am not a developer myself. I can make minor changes/modifications but that's it.
Same here, and that's the problem we've right now - we can't find enough devs :-).

I hope the best for vesta and also try to do the best to keep it alive.
Top

albertus
Posts: 12
Joined: Sat Apr 07, 2018 2:45 pm

Os: CentOS 6x
Web: apache + nginx
Re: Security discussion
  • Quote

Post by albertus » Mon Oct 08, 2018 7:20 pm

I see we have 4 options:

a) Rely on the community to find the exploited vulnerability and then fork VestaCP into something else.
b) Make a fund to offer a prize for whoever finds the hole, and then fork VestaCP.
c) Forget about VestaCP
d) Rely on the core dev team. Meaning no ETA no info until they want.

Cheers
Top

alexcy
Posts: 256
Joined: Sun Jun 01, 2014 11:24 pm
Contact:
Contact alexcy
Website

Os: Ubuntu 15x
Web: nginx + php-fpm
Re: Security discussion
  • Quote

Post by alexcy » Mon Oct 08, 2018 7:42 pm

Let's say we managed to find the hole.. After what? We need a team of devs (and a lead dev) to continue the project.

And it seems difficult to do so (at least so far).
Top

mehargags
Support team
Posts: 1096
Joined: Sat Sep 06, 2014 9:58 pm
Contact:
Contact mehargags
Website Skype

Os: Debian 8x
Web: apache + nginx
Re: Security discussion
  • Quote

Post by mehargags » Tue Oct 09, 2018 6:13 am

albertus wrote: ↑
Mon Oct 08, 2018 7:20 pm
I see we have 4 options:

a) Rely on the community to find the exploited vulnerability and then fork VestaCP into something else.
b) Make a fund to offer a prize for whoever finds the hole, and then fork VestaCP.
c) Forget about VestaCP
d) Rely on the core dev team. Meaning no ETA no info until they want.

Cheers
Trust my word, since last 2 years, I have been asking Core Vesta team to have a commercial support offering for VestaCP which will:
1) Enable VestaCP to earn some money
2) Apart from reward to the support team admins, the earned money can help us hire professional security consultants who can find vulnerabilities and polish VestaCP code further.
3) And ofcourse, include more developers in the team to speed up development.

However, I don't know why this is not being considered. We know everyone needs some financial backing to support for the hours spent as well as take a project further you also need an efficient team.
Top

pipoy
Posts: 112
Joined: Mon Sep 11, 2017 8:02 am

Os: CentOS 6x
Web: apache
Re: Security discussion
  • Quote

Post by pipoy » Tue Oct 09, 2018 12:35 pm

Deployed a droplet and and installed Cyberpanel

Pointed 1 domain from Vesta to Cyberpanel

5 min later, I destroyed Cyberpanel droplet and revert domain back to Vesta.

Vesta is irreplaceable!!!!
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: Security discussion
  • Quote

Post by dpeca » Tue Oct 09, 2018 3:47 pm

mehargags wrote: ↑
Tue Oct 09, 2018 6:13 am
Trust my word, since last 2 years, I have been asking Core Vesta team to have a commercial support offering for VestaCP
Image

and it exists since I know for VestaCP
Top


Post Reply
  • Print view

27 posts
  • Previous
  • 1
  • 2
  • 3
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

cron

Login  •  Register

I forgot my password