Pro-security? Stay away from these hosters
blog.patrolserver.com
blog.patrolserver.com
Ubuntu 12.04 LTS ships with PHP 5.3.10, and has been backporting security fixes since the PHP project EOL'd it. This will continue until April 2017.
RHEL 6 and CentOS 6 both support PHP 5.3.3, and will continue to do so for the remainder of their impressively long support cycle, until November 2020.
There's been a lot of FUD about outdated PHP versions going around in some circles, and I'm frankly very annoyed by it. Free and open-source software aren't like Windows XP. The original developer(s) announced EOL, so what? I'm under no obligation to get my PHP interpreter from the original developer(s), I get it from Red Hat and/or Canonical.
The whole point of having a stable Linux distribution is so that you can stop worrying about upstream EOL issues. Heck, RHEL/CentOS have even been backporting security fixes for PHP 5.1.6, not that any sane person would want to use that dinosaur of a version.
Some of the hosts on that list, however, are indeed using dangerously outdated PHP versions. Feel free to name and shame them.
It would also be helpful to release a table of the exact versions you found, instead of merely linking to their websites. Those who are still running PHP 5.2 deserve to be shamed even more!
Besides that, being up to date with software patches is hardly the only measurement of good security. The fact that some hosters don't even provide 2FA for your account would have me equally if not more worried, as would their practices regarding storing data and credentials.
That is the reason why security is hard ;)
As to the issues:
- Our apache was 2.2.29, it is recommended for 2.2.31 due to the 1 CVE. The re-compile is running now. Edit: It's now done.
- We use a piece of software called cloudlinux, and it features the ability to switch PHP versions. We just moved this server a few months ago and it had PHP 5.2 as the default. Admittingly, this was an oversight and I've just switched it to PHP 5.3.29. This PHP version does have security backports for CentOS/RHEL 6. This is the latest version that we can use due to our billing system. We use WHMCS, so we need to go to V6 instead of our current V5. This is a large undertaking since we need to re-theme a complex theme.
- Openssl/OpenSSH is now up to date according to the CentOS repo, which has backported patches for exploits mentioned. I'm actually not sure why this wasn't auto-updated since we had that enabled like our other servers. We don't have the experimental J-PAKE enabled, so the 2 warning vulnerabilities that your system cited are not relevant.
I've also run this your tool again on our site to confirm the openssl/openssh were fixed.
You didn't provide a contact on your blog post, would you be able to please downgrade/remove us?
Thank you.
Errr... are you determining that the software is vulnerable through the version number alone? That won't work, some vendors backport security patches.
Also I would believe that having PHP 5.3 is an unique selling point, so they would advert that unique selling point on their website. (What wasn't done)
If you're on CentOS, as a lot of web hosts are, all you need to do is `yum update` from time to time.
VPS/VDS are cheap nowadays
Shared hosting can be more secure than most self configured dedicated hosting options, simply because the hosting providers "cares" about the security in the former while outsourcing the risk to you for the most part in the latter.
If say we look at how many times a shared hosting provider was compromised (excluding stolen credentials for individual accounts since it doesn't matter if they steal your credentials for the shared control panel or for the SSH on your dedicated box) i think the picture will be quite different than what you imagine.
Big hosting providers rarely get actually compromised, on the other hand self configured dedicated hosting boxes get owned everyday by the truck load, from configuration issues to missing updates to unhardened environments they tend to be much more vulnerable.
Shared hosting providers need and do lockdown everything since their adversaries are not only external attackers but also customers with high degree of access. This doesn't just reduces the likelihood of a security issue but also reduces the impact of such issues for example SQL injection on a shared hosting will yield pretty much nothing, yes they'll be able to dump the application tables but that's it, forget about code/command execution that DB is locked down harder than one would think it's possible same thing go for other issues, local file inclusion? well GL, directory traversal, breaking out of the chroot, try agin...
Now this ofc doesn't mean that some one can't configure their own box to be just as secure for but for all effective purposes if you are running a small operation like a personal site or a site for you own small business the chances of you being able to effectively managing security at the same level of a solid hosting provider is quite slim.