Reposting the whole shit does not make it better
Possible attack on Keyhelp panels
Re: Possible attack on Keyhelp panels
Tobi
-----------------------------
wewoco.de
Das Forum für Reseller, Digital-Agenturen, Bildschirmarbeiter und Mäuseschubser
Re: Possible attack on Keyhelp panels
sudo apt update
sudo apt dist-upgrade
reboot
Re: Possible attack on Keyhelp panels
Ernsthaft? reboot geht ohne sudo?
Ich nutze normales Debian mir einem intaktem root-Account.
--
Backup: The duplicate copy of crucial data that no one bothered to make;
used only in the abstract
Re: Possible attack on Keyhelp panels
They are blocked by default. This is the current list of disable_functions, as you can see, exec, system, passthru, ... are part of it.
KeyHelp disable_functions wrote:apache_child_terminate, apache_note, apache_setenv, curl_multi_exec, define_syslog_variables, dl, exec, link, opcache_get_status, openlog, passthru, pcntl_exec, pcntl_fork, pcntl_setpriority, popen, posix_getpwuid, posix_kill, posix_mkfifo, posix_setpgid, posix_setsid, posix_setuid, proc_close, proc_get_status, proc_nice, proc_open, proc_terminate, shell_exec, stream_socket_sendto, symlink, syslog, system
Alexander Mahr
**************************************************************
Keyweb AG - Die Hosting Marke
Neuwerkstr. 45/46, 99084 Erfurt / Germany
http://www.keyweb.de - http://www.keyhelp.de
**************************************************************
Re: Possible attack on Keyhelp panels
For me it wasn't under Ubuntu 24, also in the demo they aren't.Alexander wrote: ↑Thu 21. May 2026, 10:45They are blocked by default. This is the current list of disable_functions, as you can see, exec, system, passthru, ... are part of it.
KeyHelp disable_functions wrote:apache_child_terminate, apache_note, apache_setenv, curl_multi_exec, define_syslog_variables, dl, exec, link, opcache_get_status, openlog, passthru, pcntl_exec, pcntl_fork, pcntl_setpriority, popen, posix_getpwuid, posix_kill, posix_mkfifo, posix_setpgid, posix_setsid, posix_setuid, proc_close, proc_get_status, proc_nice, proc_open, proc_terminate, shell_exec, stream_socket_sendto, symlink, syslog, system
Re: Possible attack on Keyhelp panels
Of course they are, and this is since the beginning of KeyHelp.For me it wasn't under Ubuntu 24, also in the demo they aren't.
Demo -> User administration -> Add client -> Tab PHP -> disable_functions -> There they are.
Note: They are not part of the "Unlimited" account template.
The demo client uses the "Unlimited" account template. Account templates can be modified via "Configuration -> Account templates".
Assigning the "Unlimited" template to an account does more or less that, what the name implies
Alexander Mahr
**************************************************************
Keyweb AG - Die Hosting Marke
Neuwerkstr. 45/46, 99084 Erfurt / Germany
http://www.keyweb.de - http://www.keyhelp.de
**************************************************************
Re: Possible attack on Keyhelp panels
We're using the Unlimited Template, which is why it isn’t being inserted, thx for letting know.
I've already tweaked the template over the past few days—it's now applied everywhere—BUT it's still a bit risky this way.
If you add a user without a template, it’s there—you might want to point that out.