Hacker News new | ask | show | jobs
by NickSharp 3363 days ago
For example, this tool says: https://github.com/x0rz/EQGRP/blob/master/Linux/doc/user.too...

# ELATEDMONKEY is a local privelege escalation exploit against systems running the cPanel Remote Management Web Interface, at least through version 24, and probably future versions too (althogh that should be checked before throwing).

It has been tested explicitly on cPanel 11.23.3 and 11.24.4 running CentOS 5.2 Linux

--

Those versions are from 2008/2009

1 comments

I wish I could say I'm unaware of a few thousand c5 machines still currently running prod and internet facing at just one of my previous clients; but I can't. These releases don't make things much worse than they were for those folks but let's not pretend there isnt a lot of unmaintained compute that this still applies to and that his is likely to change anytime soon.

Don't underestimate the ability of failing smbs to dismiss the risks involved with that when they can't pay to fix it.