Enable “mod_ruid2” in the “EasyApache 4” area, enable “Jail Apache” in the “Tweak Settings” area, and change users to jailshell in the “Manage Shell Access” area. Consider a more robust solution by using “CageFS on CloudLinux”. Note that this may break the ability to access mailman via Apache.
This free patch set protects your system from symlink attacks. Add KernelCare’s
Free Patch Set. Add KernelCare’s Free Symlink
Protection. NOTE: This is not the full KernelCare product and
service.
You can protect against this in multiple ways. Please review the
following documentation to find a solution
that is suited to your needs.
Reboot the system. If the problem persists, check the GRUB boot configuration.
Configure bind-address=127.0.0.1 in /etc/my.cnf or use the server’s firewall to restrict access to TCP port “3306”.
Reboot the server to ensure the system benefits from these updates.
Manually edit /etc/ssh/sshd_config and change PermitRootLogin to “without-password” or “no”, then restart SSH in the “Restart SSH” area
example.
Change these users to jailshell or noshell in the “Manage Shell Access” area.
mod_ruid2 is enabled in Apache. To ensure that this aids in protecting from symlink attacks, Jailed Apache needs to be enabled. If this not set properly, you should see an indication in Security Advisor (this page) in the sections for “Apache vhosts are not segmented or chroot()ed” and “Users running outside of the jail”. If those are not present, your users should be properly jailed. Review Symlink Race Condition Protection for further information.
Use Imunify360 for a comprehensive suite of protection against attacks on your servers.
ImunifyAV+ brings you the advanced scanning of ImunifyAV and adds more options to make protecting servers from malicious code almost effortless. Enhanced features include:
KernelCare provides an easy and effortless way to ensure that your operating system uses the most up-to-date kernel without the need to reboot your server. After you purchase and install KernelCare, you can obtain and install the KernelCare “Extra” Patchset, which includes symlink protection.
Get KernelCare for $3.00/month.
cPanel, L.L.C. uses Interface Analytics to help us understand how our customers use cPanel & WHM. We take your privacy very seriously, and you can stop data collection at any time. Find out more about Interface Analytics.
Will you allow Interface Analytics data collection for your account?