Our features site is undergoing a refresh! Be sure to explore the revamped site and discover our latest product roadmap launching here on Monday, March 18th.

EA4 Bluehost Symlink Patch

lwcpfeatures shared this idea 8 years ago
Completed

As a hosting provider I'd like cPanel to officially ship the same Bluehost symlink protection in EasyApache 4 that they did in EasyApache 3. This will maintain product capability and will prevent me from having to use a custom kernel, purchase CloudLinux, or use RUID2 in order to achieve the same protection.

Best Answer
photo

This has been added back to the WHM >> Global Configuration editor for Apache as of version 62. You can read about it in the EA4 documentation here:


https://documentation.cpanel.net/display/EA4/Symlink+Race+Condition+Protection

Replies (4)

photo
1

We've been discussing internally adding an experimental repo to EasyApache4 for testing, and this would be added to it eventually. Currently we're hitting limitations preventing building it as an RPM, but its code is available for testing on Github here:

https://github.com/JPerkster/ea-apache2-bluehost

photo
1

cP citation that it was only partially effective as the reason for removing are poor. Partial or not it would be more protection than suphp admins have now in EA4.

photo
1

I understand where you're coming from here, but we initially decided not to include it in EA4 because it's just not as good as a kernel-level patch and we wanted to encourage people to use kernel-level protection. We're considering adding it back in, however, to make it easier for user who would rather (or need to) use this patch than the kernel-level protection that is available.

photo
1

The work adding this to EA4 should be complete next week (fingers crossed), and UI support should be added to version 62. If you'd like to test what we've got, definitely send me an email: benny@cpanel.net

photo
1

This has been added back to the WHM >> Global Configuration editor for Apache as of version 62. You can read about it in the EA4 documentation here:


https://documentation.cpanel.net/display/EA4/Symlink+Race+Condition+Protection

Replies have been locked on this page!