LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Bug Reports > [RESOLVED] "No Symlink" Bypass security bug

Reply
 
Thread Tools Display Modes
  #1  
Old 02-04-2010, 04:45 AM
IrPr IrPr is offline
Senior Member
 
Join Date: Jul 2008
Posts: 147
Default [RESOLVED] "No Symlink" Bypass security bug

Hi there

Today i found that "Follow Symbolic Link" set to "No" or "If Owner Match"
its not disabling Symlink as its expected to disable whole symlinks

For example the symlink2 linked to fakesymlink/../../../../../../../../../../../../../../..//home/user/public_html/ which fakesymlink is a regular directory, when i request symlink2 through litespeed it responses 403 no permission error

but when i request for http://woot/symlink2/file.ext it will response the /home/user/public_html/file.ext file with no error!

It seems if we create a symlink to a directory, then the files in that directory are reachable through the lsws

George, Please take a look in it and update to it me ASAP

Thanks
Reply With Quote
  #2  
Old 02-04-2010, 09:34 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
Are you using LiteSpeed with Apache httpd.conf? or configure everything natively.
If you use httpd.conf, you need to use "Options" directive. otherwise, you need to set the corresponding option at vhost level as well.
Reply With Quote
  #3  
Old 02-04-2010, 10:51 AM
IrPr IrPr is offline
Senior Member
 
Join Date: Jul 2008
Posts: 147
Quote:
Originally Posted by mistwang View Post
Are you using LiteSpeed with Apache httpd.conf? or configure everything natively.
If you use httpd.conf, you need to use "Options" directive. otherwise, you need to set the corresponding option at vhost level as well.
Using cPanel and httpd.conf
All of Options directives in httpd.conf have -FollowSymlinks parameters, using LSWS 4.0.6 and 4.0.12

Would you please check it in your labs also?
Reply With Quote
  #4  
Old 02-04-2010, 10:00 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
Please do a force reinstall of 4.0.12 from web console or manually update it, it should have been fixed with latest build.
Reply With Quote
  #5  
Old 02-05-2010, 10:16 AM
IrPr IrPr is offline
Senior Member
 
Join Date: Jul 2008
Posts: 147
Quote:
Originally Posted by mistwang View Post
Please do a force reinstall of 4.0.12 from web console or manually update it, it should have been fixed with latest build.
Dear George,
Thanks for your awesome support

The bug has been fixed in the latest 4.0.12 build

Regards
Reply With Quote
  #6  
Old 03-09-2010, 05:02 AM
IrPr IrPr is offline
Senior Member
 
Join Date: Jul 2008
Posts: 147
There is still a minor bug with the symlinks

Lets assume we creare a symlink for /home/user2/public_html ( source ) directory to /home/user1/public_html/w00t (dest )

If any RewriteRule matched the request is placed in a .htaccess file in the symlink source path, it will be handled for the request

For example in the /home/user2/public_html/ path there is a htaccess to redirect all requests to https instead of http, or any hotlink protection which redirects to another url, requests for http://user2/w00t they will be redirected in order of RewriteRule located there, instead of 403 no permission

My apologize for my bad english and very bad explanation.
Reply With Quote
  #7  
Old 03-15-2010, 04:09 AM
nehaasen22 nehaasen22 is offline
New Member
 
Join Date: Mar 2010
Posts: 1
Are you using LiteSpeed with Apache httpd.conf? or configure everything natively. If you use httpd.conf, you need to use "Options" directive. otherwise, you need to set the corresponding option at vhost level as well.
__________________
Fashion
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 05:29 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.