{"id":2530,"date":"2014-08-12T09:53:44","date_gmt":"2014-08-12T13:53:44","guid":{"rendered":"http:\/\/blog.litespeedtech.com\/?p=2530"},"modified":"2014-08-12T09:53:44","modified_gmt":"2014-08-12T13:53:44","slug":"unique-litespeed-features-fight-symbolic-link-hacking","status":"publish","type":"post","link":"https:\/\/lswp.store\/index.php\/2014\/08\/12\/unique-litespeed-features-fight-symbolic-link-hacking\/","title":{"rendered":"Unique LiteSpeed Features Fight Symbolic Link Hacking"},"content":{"rendered":"<p><a href=\"http:\/\/blog.litespeedtech.com\/wp-content\/uploads\/2014\/08\/brokenchain-hi.png\"><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter wp-image-2542\" src=\"http:\/\/blog.litespeedtech.com\/wp-content\/uploads\/2014\/08\/brokenchain-hi.png\" alt=\"Broken chain\" width=\"400\" height=\"300\" srcset=\"https:\/\/lswp.store\/wp-content\/uploads\/2014\/08\/brokenchain-hi.png 600w, https:\/\/lswp.store\/wp-content\/uploads\/2014\/08\/brokenchain-hi-300x225.png 300w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/><\/a><\/p>\n<p>LSWS boasts two unique features that block symlink hacks: a\u00a0Follow Symbolic Link setting that cannot be overridden in .htaccess files and strict ownership checking.<!--more--><\/p>\n<h3>The Dangers of Symlink Hacking<\/h3>\n<p>The ways that a hacker can get unwarranted access to a server through symbolic links have been thoroughly covered in <a title=\"Sucuri blog: Symlinks to Root\" href=\"http:\/\/blog.sucuri.net\/2013\/05\/from-a-site-compromise-to-full-root-access-symlinks-to-root-part-i.html\">articles<\/a> and <a title=\"cPanel forum: Handling Symlinks\" href=\"http:\/\/forums.cpanel.net\/f185\/solutions-handling-symlink-attacks-202242.html\">forum threads<\/a> on many other sites. Hackers using symlinks escalate privileges\u00a0is a basic and widespread security issue.<\/p>\n<h3>.htaccess Immune Ownership Checking<\/h3>\n<p>This is an old trick for Apache users. Setting our <a title=\"Follow Symbolic Link setting\" href=\"http:\/\/www.litespeedtech.com\/docs\/webserver\/config\/security#followSymbolLink\">Follow Symbolic Link setting<\/a> to &#8220;If Owner Match&#8221; causes the server to only follow symlinks if the owner of the link and the target are the same. This is essentially the same as Apache&#8217;s SymLinksIfOwnerMatch option, but with one big difference: <strong>LSWS&#8217;s Follow Symbolic Link setting cannot be overridden in an .htaccess file.<\/strong> This means that, unlike with Apache, you can allow .htaccess overrides without worrying that users will bypass this basic symlink ownership checking.<\/p>\n<p><strong>LiteSpeed recommends that all shared hosting providers set Follow Symbolic Link (WebAdmin console &gt; Server &gt; Security &gt; Follow Symbolic Link) to &#8220;If Owner Match.&#8221;<\/strong><\/p>\n<h3>Force Strict Ownership Checking<\/h3>\n<p>As noted in Apache&#8217;s documentation,\u00a0<a title=\"SymLinksIfOwnerMatch documentation\" href=\"http:\/\/httpd.apache.org\/docs\/2.2\/mod\/core.html#options\">symlink testing is subject to race conditions that make it circumventable<\/a>. Specifically, this testing is vulnerable to\u00a0<a title=\"time-of-check-to-time-of-use Wikipedia article\" href=\"http:\/\/en.wikipedia.org\/wiki\/Time_of_check_to_time_of_use\">time-of-check-to-time-of-use (TOCTTOU) attacks<\/a>. A TOCTTOU attack involves changing the target location after it has been checked (by changing a symlink after the ownership check) but before a file has been opened. In order to prevent this kind of exploit, LiteSpeed has\u00a0the <a title=\"Force Strict Ownership Checking setting\" href=\"http:\/\/www.litespeedtech.com\/docs\/webserver\/config\/security#forceStrictOwnership\">Force Strict Ownership Checking setting<\/a>. <strong>Force Strict Ownership Checking prevents TOCTTOU attacks by checking the owner of the file as\u00a0the file is opened <\/strong>(when there is no chance for substitution).\u00a0This feature is similar to <a title=\"CloudLinux SecureLinks\" href=\"http:\/\/cloudlinux.com\/blog\/clnews\/introducing-securelinks-for-apache.php\">CloudLinux&#8217;s SecureLinks functionality<\/a>.<\/p>\n<p><strong>LiteSpeed also recommends that all shared hosting providers turn on Force Strict Ownership Checking\u00a0(WebAdmin console &gt; Server &gt; Security &gt; <strong>Force Strict Ownership Checking<\/strong>)\u00a0<\/strong>unless you are using CloudLinux SecureLinks.<\/p>\n<p>These settings are just one facet of LiteSpeed Web Server&#8217;s top-of-the-line security features. If you wish to learn more about security with LSWS, see the <a title=\"LiteSpeed Web Server security features\" href=\"http:\/\/www.litespeedtech.com\/products\/litespeed-web-server\/features\/built-in-security-features\">security features section<\/a> of our site.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>LSWS boasts two unique features that block symlink hacks: a\u00a0Follow Symbolic Link setting that cannot be overridden in .htaccess files and strict ownership checking.<\/p>\n","protected":false},"author":1,"featured_media":2542,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[27,23],"tags":[35],"class_list":["post-2530","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-web-server","category-security","tag-anti-hacking"],"jetpack_featured_media_url":"https:\/\/lswp.store\/wp-content\/uploads\/2014\/08\/brokenchain-hi.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/2530","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/comments?post=2530"}],"version-history":[{"count":0,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/posts\/2530\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media\/2542"}],"wp:attachment":[{"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/media?parent=2530"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/categories?post=2530"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lswp.store\/index.php\/wp-json\/wp\/v2\/tags?post=2530"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}