hostpc.com
Verified User
For the author - John?
Any thoughts?? This seems pretty "critical" ... any suggestions on patching this "hole" would be appreciated, every MB costs me money in bandwidth.
Thanks for your input.
Joe
*Note: please recognize that i am using domain1.net as an example because he is one of my friends... I am not 'illegally' using his bandwidth*
If I go to www.domain1.net/webmail I can logg in to my email account on domain2.net domain. BUT this webmail bandwidth will be charged to domain1.net.
Another thing... If I do www9.hostpc.com/webmail, there is no bandwidth charge to me, only to www9.hostpc.com... so that is a free way to check webmail...
Minor, right?
Not this way though... Say I host a 20 meg video of a wedding or whatever... I dont want to host on my account because i might go over (ok, i have 8 gig bandwidth, so i wouldn't, but bare with me) If I do link to www9.mywebserver.com/~domain2/directory/video.avi i can stream to everyone i know apparently unnoticed and un bandwidthed... This results from directadmin not knowing who to charge for hte bandwidth...
this bandwidth to www9 is speculation on my part, as I cannot see apache logs for that domain...
However, even worse is me trying to dick over domain1 (or anyone else on the domain).
If I do http://www.domain1.net/~user2/directory/video.avi i am not streaming my video THROUGH domain.net and the BANDWIDTH is charged to his account... of course in the logs it is easy to see that i am doing that, BUT it cause a good deal of confusion...
If direct admin doesn't log bandwidth by directory (which I dont beleive it does, it does by resolution and serving) then the www9.mywebserver.com/~user is a realtively nice hole to eat up free bandwidth...
Do note i have been trying this, so you will see a bunch of ~user calls in the www9 apache logs, but i am not hosting any files that are large than a few k... I was using only for testing my theory... and am not trying to steal your bandwidth... i have plently that goes unused everymonth... Just want to notify you guy because it would help to keep my domain from being outserved by another customer...
I beleive that you can stop this ~user access hole by uncommenting "Userdir public_html" line in the httpd.conf file It is something like that, i dont EXACTly remember since i am not at a comptuer that i can test that on...
this would fix the ~user hole. The /webmail hole though for www9.hostpc.com iam not so sure about... Since www9 is not hosting a webpage, I THINK you could add a /webmail redirect under the public html to redirect to a page that says "blahblhja blah use your own f-ing domain"
Any thoughts?? This seems pretty "critical" ... any suggestions on patching this "hole" would be appreciated, every MB costs me money in bandwidth.
Thanks for your input.
Joe