Slashdot Log In
cPanel Exploit Used to Circulate IE Exploit
Posted by
Zonk
on Sat Sep 23, 2006 06:27 PM
from the ouroboros dept.
from the ouroboros dept.
miller60 writes "In a dangerous combination of unpatched exploits, hackers have used a previously undiscovered security hole in cPanel to hack the servers of a hosting company and use hundreds of hijacked sites to infect Internet Explorer users with malware using the unpatched VML exploit. cPanel, whose hosting automation software is used by many large hosting companies, has issued a fix. It's a local exploit, meaning the attacker must control a cPanel account on the target hosting provider."
This discussion has been archived.
No new comments can be posted.
cPanel Exploit Used to Circulate IE Exploit
|
Log In/Create an Account
| Top
| 95 comments
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.

firefox (Score:1, Insightful)
Sure there are places where you'll get attacked often and there are others which are unlikely to be compromised but it's not enough in itself to just avoid places that look suspicious.
Re:firefox (Score:5, Interesting)
(http://commandline.org.uk/ | Last Journal: Wednesday May 30, @05:49AM)
It seems a bit odd to stick a proprietary web control panel to control a load of open-source software on an open-source web-server running on an open-source operating system.
But thats just me....
Re:firefox (Score:4, Informative)
I hope your'e patched up. Script kids have been doing the rounds with a file disclosure exploit in Webmin/Usermin for a while now. Thousands of machines have been compromised by it.
Check the miniserv.log for "..%01/..%01/..%01" or similar strings.
Temporary Fix (Score:5, Informative)
(Last Journal: Monday November 05, @02:21AM)
And to be completely safe you can unregister the
Copy the following command to clipboard and Paste into Run:
regsvr32 -u "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll"
Then when Microsoft gets around to fixing this (Probably on the next patch Tuesday) you can restore it:
regsvr32 "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll"
Want to bet this code is in Vista somewhere?
Re:Temporary Fix (Score:4, Informative)
(http://blog.mzzt.net/)
Re:Temporary Fix (Score:5, Funny)
As always.. (Score:2, Interesting)
(http://www.securityzone.org/)
Re:As always.. (Score:5, Informative)
http://forums.hostgator.com/showthread.php?t=1092
I'm a customer whose site didn't have problems, but I am satisfied with how they got on this problem. Not perfect, but definetly good. Of course when I read this headline I was shitting bricks for a moment or two.
cPanel fix (Score:5, Informative)
Owner of hostgator here (Score:4, Informative)
CPanel bugs and malware hosting combo old (Score:4, Interesting)
(http://sintixerr.wordpress.com/)
Hostgator support forum discussion on the virus (Score:5, Informative)
Hosting companies should use homemade CP (Score:1)
It does not really minimize the risk for errors, but at least it prevents exploits from spreading on the Internet.
Bluehost issued a fix. (Score:4, Interesting)
Re:Bluehost issued a fix. (Score:5, Informative)
Re:Bluehost issued a fix. (Score:4, Informative)
News about crappy software... (Score:2)
(http://kosmosik.net/)
Secondly we have some closed source software called cPanel. An ugly hack on system administration, you know the one that gives you root-like privileges over WWW. I don't know cPanel record of security but I don't care really - closed source, and unusefull (to me) stuff.
So you are using MSIE and clicking in some web frontend to administer other system. And you thought it was secure? Why?
So... as a hosting customer... (Score:2)
(http://www.littleblur.com/ | Last Journal: Wednesday June 27, @07:32PM)
I mean, I could contact my hosting provider, but I would prefer to check before harassing them.
Also, as good as they've been, I haven't really tested their professionalism before. I'd like to check w/o logging in, whether or not they say they've installed the patch. Is this remotely feasible?
Odd occurrence today (Score:3, Interesting)
My router's password dialog appears when hitting the page.
I don't think I've seen that one before.
cPanel synonym if unpatch (Score:1)
Cpanels patch doesn't work! Read!! (Score:2, Informative)
Demo accounts... (Score:1)
exploit running from hostprince.com as well? (Score:1)
Re:Someone has to.... (Score:4, Informative)
(Last Journal: Tuesday January 30 2007, @08:29PM)