Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

Able to View & Download Other Client Domains Files via a Script

General questions about VestaCP
Post Reply
  • Print view
Advanced search
8 posts • Page 1 of 1
blueberry
Posts: 25
Joined: Tue May 02, 2017 9:35 am

Able to View & Download Other Client Domains Files via a Script
  • Quote

Post by blueberry » Tue Jun 06, 2017 10:46 am

Hi, recently, we uploaded a script, and we realized that we are able to view/ download other domains files within the same server. Note that other domains belongs to different accounts. In the URL, if we know the domains, we can access the files and download them.

Not sure if this is a loophole? And is there any ways to tackle this?

We are running on the latest VestaCP on Ubuntu 16.04.

Image
Top

tjebbeke
Collaborator
Posts: 783
Joined: Mon May 11, 2015 8:43 am
Contact:
Contact tjebbeke
Website

Os: CentOS 6x
Web: apache + nginx
Re: Able to View & Download Other Client Domains Files via a Script
  • Quote

Post by tjebbeke » Tue Jun 13, 2017 8:29 am

Which web template are u using?
It looks like the open_basedir is not set properly in your template.
Top

blueberry
Posts: 25
Joined: Tue May 02, 2017 9:35 am

Re: Able to View & Download Other Client Domains Files via a Script
  • Quote

Post by blueberry » Tue Jun 13, 2017 8:48 am

Thanks for your kind reply.

Multiphp was setup following this guide, and templates from the link.

https://git.scit.ch/rs/VestaCP-MultiPHP

Can u advice how to tackle the open base dir issue?
Top

tjebbeke
Collaborator
Posts: 783
Joined: Mon May 11, 2015 8:43 am
Contact:
Contact tjebbeke
Website

Os: CentOS 6x
Web: apache + nginx
Re: Able to View & Download Other Client Domains Files via a Script
  • Quote

Post by tjebbeke » Tue Jun 13, 2017 8:57 am

Vesta doesn't support 3the party scripts and multiple PHP versions. It is better to ask the author of the multi php selector to take a look at this problem.
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: Able to View & Download Other Client Domains Files via a Script
  • Quote

Post by ScIT » Tue Jun 13, 2017 11:17 am

blueberry wrote:Thanks for your kind reply.

Multiphp was setup following this guide, and templates from the link.

https://git.scit.ch/rs/VestaCP-MultiPHP

Can u advice how to tackle the open base dir issue?
Please check your template file inside of /usr/local/vesta/data/templates/web/apache2/php{version}.tpl, you should there have the following line:

Code: Select all

        php_admin_value open_basedir %docroot%:%home%/%user%/tmp
If not, please redownload the template files: https://git.scit.ch/rs/VestaCP-MultiPHP ... -templates
Top

blueberry
Posts: 25
Joined: Tue May 02, 2017 9:35 am

Re: Able to View & Download Other Client Domains Files via a Script
  • Quote

Post by blueberry » Thu Jun 15, 2017 5:05 am

Thanks for all your advice.

I've checked and the open base dir liner is in fact in the TPL files. But still with the File Manger tool, we managed to downloaded other clients/ domains files within the same server.

Any where else we can further check?
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: Able to View & Download Other Client Domains Files via a Script
  • Quote

Post by ScIT » Mon Jun 19, 2017 8:24 am

blueberry wrote:Thanks for all your advice.

I've checked and the open base dir liner is in fact in the TPL files. But still with the File Manger tool, we managed to downloaded other clients/ domains files within the same server.

Any where else we can further check?
Can repoduce the bug on my systems, have opened a ticket to check as soon as I have some time left: https://git.scit.ch/rs/VestaCP-MultiPHP/issues/4
Top

skamasle
Collaborator
Posts: 592
Joined: Mon Feb 29, 2016 6:36 pm

Re: Able to View & Download Other Client Domains Files via a Script
  • Quote

Post by skamasle » Mon Jun 19, 2017 9:17 pm

Try 750 permisions to home or public_html will work if you try access from diferent user.
Top


Post Reply
  • Print view

8 posts • Page 1 of 1

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password