CSF security vulnerabilities and DirectAdmin

This is the problem with all of these CSF forks.

Who's forked version of CSF is affected by this? Is it cPanel's fork of CSF only?

If you fork CSF, call it something else - I don't care what, but just call it something else. Rename DirectAdmin's CSF fork to daCSF. Do something to distinguish all of the CSF forks from each other. Keep calling the binary csf if you want to, but make csf -v print something distinctive.
 
While I agree: I was asking more generally.. if DirectAdmin is aware of this and if there are plans on their side to pick up the security patches for the version it now ships with.

I know for a fact that the vulnerable code is present in the DA version, or ‘daCSF’ fork if you will ;). So mainly i’m trying to find out what DA’s plans are going forward and if it’s on their radar at all. It’s all not very public (yet).
 
Sorry, could be me but I don't get it. I don't see the fun about the dyndns option related to that.
Well, the one who controles the dns, controls your firewall. Or threat actors using cachepoisoning can get themselves fully whitelisted and disable any FW blocks completely for that ip. Every dns change is like russian roulette, at least for a while. And those are just a few issues...
 
Sorry, could be me but I don't get it. I don't see the fun about the dyndns option related to that.

The DynDNS option is potentially exploitable to allow commands to be run as root. That's part of what cPanel fixed in their CSF.

Generally it's frowned upon to spell out exactly what exploits are available in software until after it has been patched.

The discussion in this thread is basically asking if the DirectAdmin CSF is vulnerable to the same issues that cPanel patched.

The *wink* *wink* *nudge* *nudge* was meant to connect what this thread is discussing (security vulnerabilities) with that specific directive (DynDNS).
 
I think that it was already discussed:
This is only a part of it. URLGet has a serious flaw in it too, allowing infection if an attacker can control that URL. But there is more..

I also don't want to disclose more than necessary. I'm mainly hoping to get this on DirectAdmin's radar, or at least get a statement on whether they plan to pick up these fixes or not.

That said, I hadn't seen this https://forum.directadmin.com/threads/directadmin-1-707.82552/post-401591 post before starting this topic.
Searching for "CSF" on the forum understandably (search character limit) doesn't return anything.
 
Back
Top