Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

Serious concerns with security

General questions about VestaCP
Post Reply
  • Print view
Advanced search
4 posts • Page 1 of 1
gursl
Posts: 8
Joined: Sat Jan 23, 2016 1:52 pm

Serious concerns with security
  • Quote

Post by gursl » Wed Sep 25, 2019 4:49 am

Hello Vesta Team,

After several fresh installs over the years on my Vestacp with CentOS7 I think I am getting an expert of installing this system properly with no errors and latest versions stable versions of PHP MariaDB and others... maybe will do a guide on this one day :P however still I have several concerns on Security of the server.

Being VestaCP platform to facilitate the management of server I think the DEV team should leverage the security issue very seriously. I have made a scan on my website with detectify and surprisingly see so many security concerns.

Some of the issues are related to other websites however the main security points are CrossSite Scripting XSS
Which I have been trying to sort out however never succeeded. The information is all over and there is no guide on how to implement it to all Domains.
I did try to install Modsecurity and OWASP but there is no proper step by step guide adaptable to Vestacp configs.

What would you advise about server security?


Image
Top

plutocrat
Posts: 232
Joined: Fri Jan 27, 2017 9:16 am

Os: Ubuntu 17x
Web: apache + nginx
Re: Serious concerns with security
  • Quote

Post by plutocrat » Mon Sep 30, 2019 6:22 am

gursl wrote: ↑
Wed Sep 25, 2019 4:49 am
Being VestaCP platform to facilitate the management of server I think the DEV team should leverage the security issue very seriously. I have made a scan on my website with detectify and surprisingly see so many security concerns.
What software is your website running? If you pointed detectify to your website running as a domain on Vestacp, then it seems most of the issues will be to do with the configuration of that software (eg Wordpress, Joomla, etc)

The one which does leap out as a VestaCP security issue is the exposed PHPMyadmin interface. I always change the default URL of that, and put Apache Basic Auth on phpmyadmin myself, which goes a long way to mitigating the risk. (And in fact, just changing the URL would stop detectify from finding it).
Top

eris
Posts: 34
Joined: Fri Jun 26, 2020 9:25 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: Serious concerns with security
  • Quote

Post by eris » Wed Mar 03, 2021 6:02 pm

Please check:

https://github.com/serghey-rodin/vesta/issues/2045

Or https://github.com/myvesta/vesta/blob/m ... 1-feb-2021
With mulitple security issues that hasn't been patched...
Top

dpeca
VestaCP Team
Posts: 473
Joined: Wed Nov 25, 2015 7:30 pm

Re: Serious concerns with security
  • Quote

Post by dpeca » Mon Mar 15, 2021 9:08 am

Everything reported is patched in myVesta fork.

Patches are ready to be applied to official Vesta, Serghey should do that.
Top


Post Reply
  • Print view

4 posts • Page 1 of 1

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password