Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

VestaCP 0DAY

General questions about VestaCP
Post Reply
  • Print view
Advanced search
18 posts
  • 1
  • 2
  • Next
dreiggy
Posts: 154
Joined: Thu May 17, 2018 8:05 pm
Contact:
Contact dreiggy
Skype

Os: CentOS 6x
Web: apache + nginx
VestaCP 0DAY
  • Quote

Post by dreiggy » Wed Mar 18, 2020 5:27 pm

Here quite high 0day: https://pentest.blog/vesta-control-pane ... -analysis/
Top

tecob
Posts: 6
Joined: Wed Mar 08, 2017 3:29 pm

Re: VestaCP 0DAY
  • Quote

Post by tecob » Wed Mar 18, 2020 8:51 pm

Here's a perfect opportunity to prove this project is still alive and responding to critical issues!
Come on!
Top

JuzaoftheClouds
Posts: 15
Joined: Thu Feb 09, 2017 3:41 pm

Re: VestaCP 0DAY
  • Quote

Post by JuzaoftheClouds » Thu Mar 19, 2020 8:06 am

I really hope for a fix that'll solve this issue!

I can hide panel exposure on my personal host, but I think for who can't...
Top

tecob
Posts: 6
Joined: Wed Mar 08, 2017 3:29 pm

Re: VestaCP 0DAY
  • Quote

Post by tecob » Thu Mar 19, 2020 8:56 am

I think that even hiding panel exposure is not enough in this case.

If you've got a vulnerable website in your server and a malicious person installs a remote console then he will be able to modify ~/.bash_logout for example as explained here:

https://pentest.blog/vesta-control-pane ... -analysis/

then on running backup the hack is done.

Well, I think this could be possible.
Top

BartMan__X
Posts: 13
Joined: Tue Jan 16, 2018 2:58 am

Os: CentOS 6x
Web: apache + nginx
Re: VestaCP 0DAY
  • Quote

Post by BartMan__X » Thu Mar 19, 2020 2:02 pm

i fixed mine ... i installed virtualmin pro .... ill pay $6.00 for a maintained control panel
Top

exclu254
Posts: 44
Joined: Mon Dec 23, 2019 6:44 pm

Os: Ubuntu 15x
Web: nginx + php-fpm
Re: VestaCP 0DAY
  • Quote

Post by exclu254 » Thu Mar 19, 2020 2:19 pm

Oh boy! This is damn bad. ;(
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: VestaCP 0DAY
  • Quote

Post by ScIT » Thu Mar 19, 2020 2:24 pm

I already pointed on github to a fix for this problem: https://github.com/serghey-rodin/vesta/ ... -600795634
Top

tecob
Posts: 6
Joined: Wed Mar 08, 2017 3:29 pm

Re: VestaCP 0DAY
  • Quote

Post by tecob » Thu Mar 19, 2020 2:26 pm

Thanks @SciT, let's see if VestaCP developers react.
Top

exclu254
Posts: 44
Joined: Mon Dec 23, 2019 6:44 pm

Os: Ubuntu 15x
Web: nginx + php-fpm
Re: VestaCP 0DAY
  • Quote

Post by exclu254 » Thu Mar 19, 2020 2:58 pm

ScIT wrote: ↑
Thu Mar 19, 2020 2:24 pm
I already pointed on github to a fix for this problem: https://github.com/serghey-rodin/vesta/ ... -600795634
Thanks, ScIT, that is quite fast.
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: VestaCP 0DAY
  • Quote

Post by ScIT » Thu Mar 19, 2020 3:20 pm

You maybe missunderstood me: The fix was implemented for our fork called HestiaCP and is already older than a half year. I just pointed it for the vesta devs, so they can take a look - I do not have any contact to them, also the mod status I have here should have been removed since a longer time :).

It is still the part of vesta devs, to analyze our commit and implement a fix for itself.
Top


Post Reply
  • Print view

18 posts
  • 1
  • 2
  • Next

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password