Go Back   Web Hosting UK Forums | Linux Windows Dedicated Server and cPanel VPS Hosting Forum > Support > Internet Security

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-02-2008, 06:49 AM
Senior Member
 
Join Date: Feb 2008
Posts: 205
Exclamation Cpanel security release

Several potential security issues have been identified with cPanel software and Horde, a 3rd party bundled application. cPanel releases prior to 11.18.4 and 11.22.2 are susceptible to security issues, which range in severity from trivial to medium-critical. Along with the discovery of these potential issues, cPanel has released a new security tool to provide users with protection from XSRF attacks.

All STABLE and RELEASE users are strongly urged to update to their respective 11.18.5 release.

CURRENT and EDGE users should update to the latest 11.22.3 release. No releases are deemed susceptible to severe, critical or root access vulnerabilities.

cPanel has also introduced a tool designed to protect against a category of attacks known as cross-site request forgery (XSRF). This tool will validate the browser referrer information against an approved list of domains.


The list of approved domains is automatically determined according to the system's configuration. Any blocked requests are presented to the end user for approval. This additional step will minimize disruption of workflow while protecting the user from an outside XSRF attack. This check will not prevent bookmarked links in modern browsers from working normally.


XSRF protection is not enabled by default. It is controlled via WHM's Tweak Settings under the Security heading. The protection may also be enabled manually by adding the following line to the end of /var/cpanel/cpanel.config:


referrersafety=1


and restarting cpsrvd by executing /usr/local/cpanel/startup.
__________________
Midlands Weather Forum
Reply With Quote
  #2 (permalink)  
Old 05-02-2008, 09:35 AM
Dan's Avatar
Dan Dan is offline
Guru
 
Join Date: Aug 2007
Location: England, UK.
Posts: 671
Default

Usually cPanel will update automatically, hopefully
__________________
Webhosting.UK.com || cPanel VPS Hosting || Reseller Hosting || Support System || Billing System

Sales: 0808-262-0855
Support: 0800-612-8725
International: +44 191 303 8191
Reply With Quote
  #3 (permalink)  
Old 05-02-2008, 12:31 PM
Senior Member
 
Join Date: Feb 2008
Posts: 205
Default

An EDGE build won't
__________________
Midlands Weather Forum
Reply With Quote
  #4 (permalink)  
Old 05-02-2008, 12:44 PM
Dan's Avatar
Dan Dan is offline
Guru
 
Join Date: Aug 2007
Location: England, UK.
Posts: 671
Default

Didn't notice the edGe
__________________
Webhosting.UK.com || cPanel VPS Hosting || Reseller Hosting || Support System || Billing System

Sales: 0808-262-0855
Support: 0800-612-8725
International: +44 191 303 8191
Reply With Quote
  #5 (permalink)  
Old 05-03-2008, 12:32 AM
new member
 
Join Date: Apr 2008
Posts: 2
Default

can anyone please explain the XSRF in details with its benefits....
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 06:11 PM.
Copyright 2002-2007 WebHosting.uk.com. All rights reserved.
Web Hosting UK Forum