Own a Server? (Remove Fantastico now)

Posted by BitSurFer, 04-30-2007, 08:31 PM
Hello EveryOne If you have Fantastico installed in your server Remove it now or you will get hacked they can get your server root I can't paste the exploit here Thanks

Posted by boonchuan, 04-30-2007, 08:54 PM
Maybe you can contact Fantastico of what you have found and give them the exploit, this will help far more people than posting it here.

Posted by Alex, 04-30-2007, 09:19 PM
Yes, how do we know your information is even valid? I would say 95% of all Fantastico hacks are really just people who don't bother to update Fantastico installed scripts. That being said, I don't have Fantastico on any of my boxes, and will probably never have it, due to the security problems that come from users installing old scripts and forgetting about them. I would much rather take 5 minutes to install the script for the user correctly than let a script on the server attempt to do it. Alex

Posted by SoFiMaN, 04-30-2007, 09:22 PM
I am not using fantastico but I heared there was one long time ago and I believe they fixed it. If its a new one I would do as boonchaun said and contact them directly. Last edited by SoFiMaN; 04-30-2007 at 09:33 PM.

Posted by whmcsguru, 05-01-2007, 03:10 AM
While it's never advisable to post an exploit publically, it makes you look bad when you refuse to post at least some details of the exploit, and takes credibility away from you. Fantastico itself is most likely NOT vulnerable, but an internal application of it MAY be (most likely one of the *nukes or WP). Without details again, your credibility is pretty much shot.

Posted by bdwarr6, 05-01-2007, 05:04 PM
I am sure that if it was a widespread issue with the latest version we would be hearing alot more about it as thousands if not close to a million servers are running it.

Posted by jpetersen, 05-05-2007, 12:14 PM
BitSurFer - was there ever anything to validate your claims, or was this just FUD?

Posted by Galaxy-Hosts, 05-05-2007, 12:30 PM
I think the OP is referring to this exploit http://milw0rm.com/exploits/3459 . That exploit has been patched http://www.netenberg.com/forum/viewtopic.php?t=5614 . So rather than uninstalling Fantastico, just make sure it is updated.

Was this answer helpful?

 Print this Article

Also Read

Q: Prevent DDoS attacks with restarting httpd ?

Posted by NameTyper, 01-12-2008, 11:36 AMHi all Just a short question. Can you restart the...

How is the service ?

Posted by aboovk, 09-04-2002, 01:06 AMHi, I need a resellers plan with 10 virtual domain...

Avoiding cleartext passwords for mysql connection

Posted by DataCentric, 02-08-2011, 03:48 PMHey guys, Any bright ideas on how to better secure...

Please help me with Plesk and Qmail

Posted by biggies, 04-21-2009, 11:30 AMHi, I have server running Plesk 8.6 with Qmail....

Resellers Plan

Posted by aboovk, 09-03-2002, 08:48 AMHi, Can any one please tell me about some good reselles...