Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Member
    Join Date
    Nov 2003
    Location
    Indianapolis, IN
    Posts
    13

    Default Server was hacked via cPanel demo...

    This morning my server with EV1 was hacked. The EV1 support center determined that the hacker made his way into the system via the cPanel demo I had available on my server. The hacker was able to upload a file into my /tmp directory that was performing DOS attacks.

    Now I really like cPanel but it's a shame that their own demo mode isn't secure. Needless to say I won't be offering a demo mode anymore and I wanted to share this eith everyone else.

    If you have any questions I'll gladly answer them but I will say everything on my server was up to date.

  2. #2
    Member
    Join Date
    Sep 2001
    Posts
    105

    Default

    This is possibly related to the php issue I reported earlier in the week.

  3. #3
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Originally posted by GordonH
    This is possibly related to the php issue I reported earlier in the week.
    Which has been fixed according to the changelog, but only in EDGE...

  4. #4
    Member
    Join Date
    Sep 2001
    Posts
    105

    Default

    Yes, I dont like updating to edge.
    Its OK if you have one or 2 servers but we have nearly 60 and if there is a bug in the edge release it can be a nightmare to try and deal with across so many boxes.

  5. #5
    Member netwrkr's Avatar
    Join Date
    Apr 2003
    Posts
    203

    Default

    Originally posted by GordonH
    This is possibly related to the php issue I reported earlier in the week.
    Can anyone confirm this PHP bug has been exploited on a cPanel server? What is cPanel doing to fix this? If this is a remotely exploitable vulnerability Nick needs to get on the ball and push out a fix in a release update now.

  6. #6
    Member qbert1987's Avatar
    Join Date
    Dec 2003
    Location
    Canberra, Australia
    Posts
    130

    Default

    anyone herd from the achal cpanel people about this, im keen for a fix so i can offer a demo...
    Last edited by qbert1987; 01-13-2004 at 07:39 AM.

  7. #7
    Member
    Join Date
    Nov 2003
    Posts
    521

    Default

    it would be nice to have a timeframe on when the next stable release of cpanel would actually be released.

  8. #8
    Member netwrkr's Avatar
    Join Date
    Apr 2003
    Posts
    203

    Default

    Originally posted by damainman
    it would be nice to have a timeframe on when the next stable release of cpanel would actually be released.
    agreed. Been almost 3 months already.

Similar Threads & Tags
Similar threads

  1. Migrating to clean cpanel from a hacked server
    By cfconcepts in forum Security
    Replies: 1
    Last Post: 09-14-2010, 12:00 PM
  2. stelaartois.ru - cpanel server hacked ?
    By forlinuxsupport in forum Security
    Replies: 26
    Last Post: 06-23-2008, 02:17 PM
  3. stelaartois.ru - cpanel server hacked ?
    By forlinuxsupport in forum cPanel and WHM Discussions
    Replies: 26
    Last Post: 06-23-2008, 02:17 PM
  4. cPanel Demo server - out of space
    By viptexting in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-10-2007, 08:53 AM
  5. cPanel Demo Server?
    By MattF in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 09-24-2003, 08:15 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube