Post Reply 
Why is Awstats implemented? -> security risk
Author Message
monotek Offline
Junior Member
*

Posts: 46
Joined: Dec 2006
Reputation: 0
Post: #1
Why is Awstats implemented? -> security risk
Why is awstats implemented in upcoming omega release?
Imho thats a security risk. More than one time there was ugly bugs which could be used to compromise a server using awstats.

Sure Awstats looks nice but is webalizer not enough anyway?

Is awstats only optional or is it always used?
12-02-2006 05:50 AM
Find all posts by this user Quote this message in a reply
Shin Away
Junior Member
****
Dev Team

Posts: 67
Joined: Oct 2006
Reputation: 0
Post: #2
RE: Why is Awstats implemented? -> security risk
You can disable it from the code, but it is better that webalizer
12-02-2006 06:20 AM
Visit this user's website Find all posts by this user Quote this message in a reply
monotek Offline
Junior Member
*

Posts: 46
Joined: Dec 2006
Reputation: 0
Post: #3
RE: Why is Awstats implemented? -> security risk
Yes ist is. And sometimes unsecure.
What do you mean with "You can disable it from the code"?
Will there be a config option to choose webalizer or awstats?
12-02-2006 06:23 AM
Find all posts by this user Quote this message in a reply
Shin Away
Junior Member
****
Dev Team

Posts: 67
Joined: Oct 2006
Reputation: 0
Post: #4
RE: Why is Awstats implemented? -> security risk
no that you can modify the vhcs code for webalizer use
12-02-2006 06:32 AM
Visit this user's website Find all posts by this user Quote this message in a reply
ephigenie Offline
Administrator
*******
Administrators

Posts: 671
Joined: Oct 2006
Reputation: 12
Post: #5
RE: Why is Awstats implemented? -> security risk
later on we could think over adding modlogan support i.e.
12-02-2006 11:18 PM
Visit this user's website Find all posts by this user Quote this message in a reply
Donni Offline
Junior Member
*

Posts: 13
Joined: Nov 2006
Reputation: 0
Post: #6
RE: Why is Awstats implemented? -> security risk
Why not integrate Awstats with static page generation? If you use it with this option all output pages are pure html pages and there should be no security risk. AFAIR there is a "awstats static howto" somewhere in the official forum.
12-05-2006 06:27 PM
Find all posts by this user Quote this message in a reply
RatS Offline
The Project's Fire Worker
******

Posts: 701
Joined: Oct 2006
Reputation: 18
Post: #7
RE: Why is Awstats implemented? -> security risk
Yes, there is, it's made by me ...
The trunk is only a WIP-Version, please be patient!
12-06-2006 04:36 AM
Visit this user's website Find all posts by this user Quote this message in a reply
monotek Offline
Junior Member
*

Posts: 46
Joined: Dec 2006
Reputation: 0
Post: #8
RE: Why is Awstats implemented? -> security risk
Is this changed to static genration yet?
03-16-2007 11:30 PM
Find all posts by this user Quote this message in a reply
BeNe Offline
Moderator
*****

Posts: 3,168
Joined: Jan 2007
Reputation: 42
Post: #9
RE: Why is Awstats implemented? -> security risk
I dont think so - Integrate AwStats support is change in the Roadmap to Omega 1.0.0.

[Image: ispcpsw.png]
Ein Betriebssystem ist immer nur so gut und sicher wie der Administrator der es verwaltet.
Wie gut der Administrator jedoch seine Fähigkeiten ausspielen kann, legt das Betriebssystem fest.
-> Linux rulZ!
03-16-2007 11:40 PM
Visit this user's website Find all posts by this user Quote this message in a reply
BioALIEN Offline
Junior Member
**
Graph Team

Posts: 247
Joined: Feb 2007
Reputation: 0
Post: #10
RE: Why is Awstats implemented? -> security risk
I prefer AWStats to Webalizer. I know more newbie sys admins will convert to VHCS Omega because of this fact Smile

BioALIEN
OS: Debian 4.0 Etch
ispCP Build: RC3 r953 - 28.12.07
Mods: AWStats dynamic
03-17-2007 01:54 AM
Find all posts by this user Quote this message in a reply
Post Reply 


Forum Jump:


| All rights reserved : isp-control.net |