Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Security Hole in Cloud Hosting Control Panels - Article: Vladimir vs Hosting Industry

Security Hole in Cloud Hosting Control Panels - Article: Vladimir vs Hosting Industry

Scheduled Pinned Locked Moved Discuss
wordpresssecurityvulnerability
5 Posts 2 Posters 935 Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J Offline
    J Offline
    jagan
    wrote on last edited by jagan
    #1

    Hi everyone, I came across this article that might be of interest.

    Teaser: Vladimir vs Hosting Industry

    This is what I gathered from the article, and I am no expert:

    Vladimir Smitka, a security researcher/hobbyist from the Czech Republic has found that one weak or compromised site on a server can be used to control / manipulate and gain access to other sites on the same server.

    That is, many run multiple wordpress sites on a single server - some of these sites are just test or hobby sites that are not secured very well.
    These sites, if compromised, can be used to launch attacks on other sites on the same server even if the installations are isolated dockers.

    Seems like most famous web panel providers like Cloudways, RunCloud, etc have failed the test and more importantly have not taken any steps to address the issue and patch the vulnerabilities.

    Providers I tested:

    Serveravatar – didn’t found the way how to break site isolation (but was able to bypass some default security measures and you have to be very careful with some of the features)
    Enhance.com -fixed instantly
    InstaWP – fixed
    Xcloud.host – fixed
    GridPane – fixed most issues pretty quick
    Ploi – investigating for 2 months, will be fixed soon
    Cloudways – not fixed after 3 months
    RunCloud – investigating few weeks, not fixed yet
    FlyWP – investigating more than month, not fixed yet
    Cloudpanel – will be fixed in distant future
    SpinupWP – feature not a bug
    Forge – don’t care

    Conclusion: Docker doesn’t automatically guarantee security.

    Should we be worried?
    What measures are you currently taking to secure your WP sites.
    And what are some good practices that we must adopt?

    1 Reply Last reply
    3
    • J Offline
      J Offline
      jagan
      wrote on last edited by
      #2

      My first reaction on reading about cloudways was to smirk at them and feel smug about my decision to abandon that sinking ship of a platform (constant upsells for almost everything), but it hit me - I mustn't be so cocky.

      Let me check with our friendly community.

      1 Reply Last reply
      1
      • girishG Offline
        girishG Offline
        girish
        Staff
        wrote on last edited by
        #3

        I guess we need to see more technical details to see if Cloudron package might be affected.

        1 Reply Last reply
        3
        • J Offline
          J Offline
          jagan
          wrote on last edited by
          #4

          The part two with exploit code, some possible fixes and details has been posted.
          https://smitka.me/2024/06/08/vladimir-vs-hosting-industry-docker-php-fpm/

          1 Reply Last reply
          2
          • girishG Offline
            girishG Offline
            girish
            Staff
            wrote on last edited by girish
            #5

            @jagan from a quick reading, this doesn't apply to Cloudron, since we don't use fpm for WordPress (we use modphp)

            1 Reply Last reply
            2
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Don't have an account? Register

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • Bookmarks
            • Search