![]() |
|
Hight Security Vulnerabilities - Printable Version +- Sentora Support Forums (https://senforums.mach-hosting.com) +-- Forum: Sentora Forum Archives (https://senforums.mach-hosting.com/forumdisplay.php?fid=5) +--- Forum: Sentora Public Support Forums v1.0.x (https://senforums.mach-hosting.com/forumdisplay.php?fid=32) +---- Forum: General Support Forum v1.0.x (https://senforums.mach-hosting.com/forumdisplay.php?fid=36) +---- Thread: Hight Security Vulnerabilities (/showthread.php?tid=1927) Pages:
1
2
|
Hight Security Vulnerabilities - Riperino - 09-05-2015 This is true? http://www.lowendtalk.com/discussion/47220/sentora-alternative-to-zpanel-warning ZPanel have this security problem and it seems the Sentora equals. Normally all control panels are usually accessed via SSL such as https://1234.1234.1234.1234:8080 but this panel does not. I think it is already time to correct these vulnerabilities because the control panel until is pretty good and it's a shame anyone able to hack the system and compromise all the data we have on the server. RE: Hight Security Vulnerabilities - apinto - 09-05-2015 Seriously? Again? - http://forums.sentora.org/showthread.php?tid=1289 - http://forums.sentora.org/showthread.php?tid=1903 - http://forums.sentora.org/showthread.php?tid=1759 - http://forums.sentora.org/showthread.php?tid=1750 This is old and fixed... meh... Also, you can setup SSL, Sentora Fully supports it, however like ANY OTHER PANEL you need to enable a Certificate on your server and domain, Sentora cant do that for you. If you know of any security issue, show it, usually the Sentora Dev team and community fixes this really fast (latest security issue got a Hot Fix released in less than 24h after report). RE: Hight Security Vulnerabilities - Riperino - 09-05-2015 (09-05-2015, 11:42 PM)apinto Wrote: Seriously? Again? I'm sorry I did not know... So I'm relieved and I can use without any problem. Thanks. RE: Hight Security Vulnerabilities - apinto - 09-06-2015 It's ok. Just make sure you verify everything and do not only read the first post from half an year ago
RE: Hight Security Vulnerabilities - Riperino - 09-06-2015 (09-06-2015, 01:52 AM)apinto Wrote: It's ok. Ok ![]() But can not make the safest login on control panel? Per example, Instead of entering the subdomain (panel.mydomain.com) or directly by IP (123.123.123.123), can enter through a port (123.123.123.123:8080). This made the safest access because any intelligent person could have access to the login of the control panel. RE: Hight Security Vulnerabilities - mettacell - 09-06-2015 (09-06-2015, 06:13 AM)Riperino Wrote:(09-06-2015, 01:52 AM)apinto Wrote: It's ok. I could be wrong, but I think it's already there. Go to Admin>Sentora Config and change the Sentora Apache Port, change the port 80 to any desired, legit port. On next deamon run the change shall take place.Long ago I did it manually with zPanel by editing vhost. But it was unstable. Better do it from admin panel. hope this helps.
RE: Hight Security Vulnerabilities - Me.B - 09-06-2015 My advice if you use the panel for personal use and don't provide login for any one best is moving the panel to another port & locking it with IPtables rules. Beside that any vulnerability reported was fixed. M B RE: Hight Security Vulnerabilities - Riperino - 09-06-2015 (09-06-2015, 07:39 PM)Me.B Wrote: My advice if you use the panel for personal use and don't provide login for any one best is moving the panel to another port & locking it with IPtables rules. But how can I add a port to log in to my control panel? Since I am thinking create accounts for other users and would be ideal not be able to access the login directly through the IP. RE: Hight Security Vulnerabilities - Me.B - 09-06-2015 It's a hardening ADVICE ! I meant if you you use it that way and add the firewall restriction, you will end up locking down any further risk. RE: Hight Security Vulnerabilities - Riperino - 09-06-2015 (09-06-2015, 11:08 PM)Me.B Wrote: It's a hardening ADVICE ! I meant if you you use it that way and add the firewall restriction, you will end up locking down any further risk. And how can I do this? I use CSF Firewall. |