Upgrading a cPanel plugin
zamfoo.com
zamfoo.com
[1] - http://www.webhostingtalk.com/showthread.php?t=1275572 [2] - http://www.webhostingtalk.com/showpost.php?p=8727714&postcou... [3] - http://localhost.re/p/zamfoo-120-vulnerability
[1] http://www.reddit.com/r/programming/comments/1gfve8/how_not_...
[2] http://www.reddit.com/r/programming/comments/1gfve8/how_not_...
I tried submitting it to HN, but I receive an error "stop spamming us, you are wasting your time". Anyone knows why this is? (I'm most definitely not a spammer)
I agree that the responses from the company in the linked thread are awful.
_REALLY?_
The mind reels.
That would make about as much sense as everything else they've done....
Composer (for PHP) [2] also uses this install method, but you can just download the Phar file from their Web site directly -- all the sh script does is check PHP settings and dependencies.
"not only that. there is an emergency kill switch. if you release the patch i will pull the switch and no one can use the software. your exploit will not work if i do that. the plugin will become useless until i turn it back on."
[1] http://www.webhostingtalk.com/showpost.php?p=8724954&postcou...
I guess we should change our root passwords to "root123" so upgrading becomes easier.
ultimately, it's up to customers and end users to decide if they can tolerate a security hole being open for a few weeks or months. to that end, maybe it's better to go down the food chain and look at what hosts are using WHM, and publish that list. end users could see if their provider is exposed.
2. It seems like this is mostly a one-person shop, with the site owner answering the emails and forum discussions. Ugh, nothing like having to maintain holey software yourself...though obviously, I feel much sorrier for anyone who's gotten/is getting hacked.
If you're wondering what the practical purpose of this is... there isn't one, really. But apparently some WHM resellers (and iterated resellers, I suppose) are interested in this sort of thing for some reason, so it exists.
Personally, I just feel sorry for the end users at the far end of this software, behind as many as three or four levels of reselling. That's got to be a pretty damn awful customer experience.
http://en.wikipedia.org/wiki/WHM#WHM_.28Web_Host_Manager.29
> WebHost Manager (WHM) is a web-based tool used by server administrators and resellers to manage hosting accounts on a web server. WHM listens on ports 2086 and 2087 by default.
I was thinking it meant "warehouse management", with all the "reselling" involved...I also figured the kind of people who might install it are looking for some quick fix (if insecure) software to manage their warehouses...