{"id":4476,"date":"2019-04-05T05:39:00","date_gmt":"2019-04-05T05:39:00","guid":{"rendered":"https:\/\/www.icdsoft.com\/blog\/?p=4476"},"modified":"2019-04-08T14:12:06","modified_gmt":"2019-04-08T14:12:06","slug":"apache-cve-2019-0211-and-shared-hosting-providers","status":"publish","type":"post","link":"https:\/\/www.icdsoft.com\/blog\/apache-cve-2019-0211-and-shared-hosting-providers\/","title":{"rendered":"Apache CVE-2019-0211 and Shared Hosting Providers"},"content":{"rendered":"\n<p>In the past few days, big tech media outlets rotated a news item about a vulnerability in the Apache Web Server - <a rel=\"noreferrer noopener\" aria-label=\"CVE-2019-021 (opens in a new tab)\" href=\"https:\/\/cfreal.github.io\/carpe-diem-cve-2019-0211-apache-local-root.html\" target=\"_blank\">CVE-2019-0211<\/a>. Apache powers more than 40% of the Internet and is the most popular web server today. You can check the following article on <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/arstechnica.com\/information-technology\/2019\/04\/serious-apache-server-bug-gives-root-to-baddies-in-shared-host-environments\/ \" target=\"_blank\">Ars Technica <\/a>for example.<br><\/p>\n\n\n\n<p>All articles we saw mentioned that the bug is particularly bad for shared hosting providers. This may be the case for some, but ICDSoft's hosting environment is protected from such exploits by <u>design.<\/u><\/p>\n\n\n\n<p>This is a privilege escalation bug. It theoretically allows unprivileged scripts, usually run by Apache with lowered privileges, to take over the main Apache process. In some environments, the main Apache process may be running as <strong>root,<\/strong> which in turn would allow the unprivileged script to gain <strong>root <\/strong>access.<\/p>\n\n\n\n<p>We have heard the same tune many times - shared hosting providers are insecure and you should be using a VPS. Our practice as a shared hosting provider for over 18 years has shown exactly the opposite, and this bug proves it. Here is why:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>ICDSoft's servers were never vulnerable to this bug. It affects only badly configured servers. In this case, we are protected by a security mechanism called <strong>SuExec<\/strong>.<\/li><li>ICDSoft's system administrators were updating the servers with the provided patches (which were largely unneeded in our case) even before the big news outlets posted the news. <\/li><\/ul>\n\n\n\n<p>If you check only the headlines, you may get only a part of the picture. This is also the case with the following post, which popularized the bug in the security circles:<\/p>\n\n\n\n<figure class=\"wp-block-embed-twitter wp-block-embed is-type-rich is-provider-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Flaw in Apache HTTP Server 2.4.17 - 2.4.38 allows anyone you allow to write a script (PHP, CGI,..) to gain root.  Get 2.4.39 *now* especially if you have untrusted script authors or run shared hosting (or use mod_auth_digest, due to a separate flaw)<a href=\"https:\/\/t.co\/s08XhOzKKW\">https:\/\/t.co\/s08XhOzKKW<\/a><\/p>&mdash; Mark J Cox (@iamamoose) <a href=\"https:\/\/twitter.com\/iamamoose\/status\/1112966189276389376?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 2, 2019<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n\n<p>However, scrolling down the thread reveals the truth - properly secured setups are unaffected:<\/p>\n\n\n\n<figure class=\"wp-block-embed-twitter wp-block-embed is-type-rich is-provider-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Good q, though not sure we can write simple wording to cover all different ways of running scripts via httpd.  The exploit is possible for an attacker executing code with the privileges of an httpd child - hence that would exclude scripts executed via suexec.<\/p>&mdash; Joe Orton (@notroj) <a href=\"https:\/\/twitter.com\/notroj\/status\/1112989933613056000?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">April 2, 2019<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n\n<p><br><\/p>\n\n\n\n<p>So, if you are reading the news and are concerned about shared hosting, don't be. At least if you are using <strong>ICDSoft<\/strong>. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn more about Apache&#8217;s vulnerability CVE-2019-0211 and why it doesn&#8217;t affect ICDSoft customers.<\/p>\n","protected":false},"author":1,"featured_media":4516,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","footnotes":""},"categories":[2,6,5],"tags":[],"class_list":{"0":"post-4476","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-security","9":"category-tech"},"author_meta":{"display_name":"ICDSoft","author_link":"https:\/\/www.icdsoft.com\/blog\/author\/icdsoft\/"},"featured_img":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/apache2-300x140.jpg","featured_image_src":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/apache2.jpg","featured_image_src_square":"https:\/\/www.icdsoft.com\/blog\/wp-content\/uploads\/2019\/04\/apache2.jpg","author_info":{"display_name":"ICDSoft","author_link":"https:\/\/www.icdsoft.com\/blog\/author\/icdsoft\/"},"coauthors":[],"tax_additional":{"categories":{"linked":["<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/news\/\" class=\"advgb-post-tax-term\">News<\/a>","<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/security\/\" class=\"advgb-post-tax-term\">Security<\/a>","<a href=\"https:\/\/www.icdsoft.com\/blog\/category\/tech\/\" class=\"advgb-post-tax-term\">Technology<\/a>"],"unlinked":["<span class=\"advgb-post-tax-term\">News<\/span>","<span class=\"advgb-post-tax-term\">Security<\/span>","<span class=\"advgb-post-tax-term\">Technology<\/span>"]}},"comment_count":"0","relative_dates":{"created":"Posted 7 years ago","modified":"Updated 7 years ago"},"absolute_dates":{"created":"Posted on April 5, 2019","modified":"Updated on April 8, 2019"},"absolute_dates_time":{"created":"Posted on April 5, 2019 5:39 am","modified":"Updated on April 8, 2019 2:12 pm"},"featured_img_caption":"","series_order":"","_links":{"self":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/4476","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/comments?post=4476"}],"version-history":[{"count":19,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/4476\/revisions"}],"predecessor-version":[{"id":4577,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/posts\/4476\/revisions\/4577"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/media\/4516"}],"wp:attachment":[{"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/media?parent=4476"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/categories?post=4476"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.icdsoft.com\/blog\/wp-json\/wp\/v2\/tags?post=4476"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}