{"id":290,"date":"2016-12-21T10:58:15","date_gmt":"2016-12-21T10:58:15","guid":{"rendered":"https:\/\/puvox.software\/?p=290"},"modified":"2021-11-14T13:45:49","modified_gmt":"2021-11-14T13:45:49","slug":"restrict-php-access-upper-directory","status":"publish","type":"post","link":"https:\/\/puvox.software\/blog\/restrict-php-access-upper-directory\/","title":{"rendered":"Restrict PHP upper directory access &#8211;  PROTECTION FROM HACK !"},"content":{"rendered":"<div class=\"default-content-clss content_290 type_post \"><p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-1648 size-full\" src=\"https:\/\/puvox.software\/wp-content\/uploads\/2016\/12\/php-folder-access.png\" alt=\"php access directory\" width=\"424\" height=\"164\" \/><\/p>\n<h1 style=\"text-align: center;\"><span style=\"color: #ff6600;\">Security problems with cPanel !<\/span><\/h1>\n<p style=\"text-align: center;\"><strong>Pre-amble<\/strong><\/p>\n<p>I think it is the HIGHEST-LEVEL security matter for EVERYONE, WHO HAVE A WEBSITE.\u00a0Probably everyone knows &#8211; when you host multiple domains in <a href=\"https:\/\/cpanel.com\/\">cPanel<\/a>, then they are listed in same FTP (even though in different folders). Unfortunately, that is default functionality of cPanel&#8217;s end-user dashboard, and probably you might have\u00a0<strong>never imagined how important security problem<\/strong> that lies behind it. You might thought one &#8211; &#8220;who needs to hack my site?&#8221; and then forget to care about security of your site&#8230;<\/p>\n<p>Well, <strong>that is the HUGE mistake<\/strong>!<\/p>\n<p>Hackers (with internet BOTS) not always\u00a0 hack your site to steal your money directly, but they do a lot of other things &#8211; stealing your information, identification info, users&#8217; passwords and email addresses, visitors information, marketing info, links, website authority and much more. And thus, they get a big profit from any typical hacked site ..<\/p>\n<h2 style=\"text-align: center;\">Can cPanel Restrict access from FTP\/Domain folder?<\/h2>\n<p>So, when you added separate domains in the same FTP, you were thinking that they were &#8220;separated&#8221; &#8211; Actually, <strong>that is not true<\/strong>. Although FTP users could be separated and restricted to specific directory, that restriction doesn&#8217;t relate to core PHP! <strong>Any of PHP file (wherever it is) CAN ACCESS ANY UPPER DIRECTORY<\/strong> !\u00a0 <span style=\"color: #ff6600;\">(DONT TRUST HOSTING&#8217;S SUPPORT GUY, WHO IS TELLING YOU THAT DOMAINS ARE SEPARATED! They dont know what they say &#8211; Try this <a href=\"https:\/\/pastebin.com\/raw\/gJsPVqUt\">simple php filemanager<\/a> from any of our sub-sites and you will see, PHP can access any folder in your account ! )<\/span><br \/>\nSo, if one of your domains gets hacked, then the hacker(or bot) can access\u00a0 whole FTP and all your hosted domains and databases easily. And &#8211; we see hundreds of hacked WordPress websites every-day, that&#8217;s because people don&#8217;t take care of their website security.<\/p>\n<p>Well, when you are going to host multiple domains, and secure them, then the only solution is to get a different USERNAME ROOT for each domain i.e. :<\/p>\n<pre>\/home\/<strong>username1<\/strong>\/public_html\/\r\n\/home\/<strong>username2<\/strong>\/public_html\/\r\netc...<\/pre>\n<p>However, that is not possible with regular cPanel accounts (a.k.a. &#8220;shared hosting&#8221;), because all &#8220;add-on&#8221; domains are put under the same username account directory, like:<\/p>\n<pre>\/home\/username\/domain1.com\/\r\n\/home\/username\/domain2.com\/\r\netc..<\/pre>\n<p><span style=\"color: #999999;\"><em>(That means, all files in a CPANEL account are owned by the same user. So, same user&#8217;s PHP can access everything from everywhere. Some people said, PHP restrictions could be achieved by using <strong><code>open_basedir<\/code><\/strong> and <strong><code>safemode<\/code><\/strong>[disables EXEC(),shell_exec,system(),passthru,readfile,escapeshellarg,escapeshellcmd,proc_close. and etc..] options (from php.ini), and <code><strong>AllowOveride<\/strong><\/code> option (globally from httpd.conf. NOTE:this file is not available for most shared hostings), but even these options doesnt help, because <strong><code>cgi-bin scripts<\/code><\/strong> and <strong><code>cronjobs<\/code><\/strong> remains still unprotected..)<\/em><\/span><\/p>\n<p>However, that could be annoying for many people.<span style=\"color: #ff0000;\"><strong>\u00a0BUT, I HAVE FOUND ANOTHER SOLUTION.<\/strong><\/span><\/p>\n<p>&nbsp;<\/p>\n<h2 style=\"text-align: center;\">Solution to Protect any domain\/website\/FTP<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1650 size-medium\" src=\"https:\/\/puvox.software\/wp-content\/uploads\/2016\/12\/security-1-1-265x300.png\" alt=\"\" width=\"265\" height=\"300\" srcset=\"https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2016\/12\/security-1-1-265x300.png 265w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2016\/12\/security-1-1-400x453.png 400w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2016\/12\/security-1-1-768x870.png 768w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2016\/12\/security-1-1-904x1024.png 904w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2016\/12\/security-1-1-238x270.png 238w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2016\/12\/security-1-1-60x68.png 60w, https:\/\/puvox.software\/blog\/wp-content\/uploads\/sites\/2\/2016\/12\/security-1-1.png 916w\" sizes=\"(max-width: 265px) 100vw, 265px\" \/><\/p>\n<p>To prevent PHP scripts from accessing files between domains, you would need one of the following:<\/p>\n<p>1) to create the domains as separate CPANEL accounts. This requires root access to the server (i.e. VPS or Dedicated), or a <b>RESELLER <\/b>account(that has access to WHM),\u00a0from where you can create separate accounts, and then host only 1 domain in one account.<\/p>\n<p>2) Some people say (but I have not tested personally) is to have <a href=\"https:\/\/www.directadmin.com\/\">DirectAdmin <\/a>(several hosting companies offer that). You can create subdomains under different <b>User accounts<\/b>, so each sub.domain.com User can have their own DirectAdmin User account (You&#8217;d just enter domain=sub.domain.com for each User).<\/p>\n<p><b>3) Best thing &#8211; obtain a hosting, where the domains are added in separate, restricted root\u00a0directories (some hosting companies have such system).\u00a0 You can find out the list here : <a href=\"https:\/\/puvox.software\/blog\/cheap-hosting-list-comparations\/\">Comparison of secure hosting companies<\/a><\/b><\/p>\n<p>4) Another useful trick: If you want to use <span style=\"color: #808080;\"><a href=\"http:\/\/wordpress.org\">WordPress<\/a> <\/span>CMS and under your server, which you want give them to other people (and dont want to fear of them, hacking your site) then\u00a0give other people only &#8220;<strong>AUTHOR<\/strong>&#8221; role-users. So, you will be safer.\u00a0 \u00a0(About WordPress &#8211;\u00a0 you should also review <a href=\"https:\/\/puvox.software\/blog\/must-have-wordpress-plugins\/\"><strong>Must-Have WordPress Plugins<\/strong><\/a> (especially, read the &#8220;<span style=\"color: #ff0000;\"><strong>Guard<\/strong><\/span>&#8221; plugins) to even secure your individual websites.\u00a0You should install several plugins, like\u00a0\u00a0<b>iThemes Security, Sucuri<\/b>, BlackBots and etc,,<b>)<\/b><\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<div class=\"default-content-clss excerpt_290 type_post \"><p>Security problems with cPanel ! Pre-amble I think it is the HIGHEST-LEVEL security matter for EVERYONE, WHO HAVE A WEBSITE.\u00a0Probably everyone knows &#8211; when you host multiple domains in cPanel,<a class=\"excerpt-read-more\" href=\"https:\/\/puvox.software\/blog\/restrict-php-access-upper-directory\/\">(Continue Reading)<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":1650,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[13],"tags":[],"class_list":["post-290","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-website"],"_links":{"self":[{"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/posts\/290","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/comments?post=290"}],"version-history":[{"count":0,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/posts\/290\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/media\/1650"}],"wp:attachment":[{"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/media?parent=290"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/categories?post=290"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/puvox.software\/blog\/wp-json\/wp\/v2\/tags?post=290"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}