CXS (Config Server) experience?

postcd

Well-Known Member
Oct 22, 2010
717
19
68
Hello,

i know there is a tool called CXS to detect bad scripts on cpanel hosting accounts during upload (ftp, web. exploit)

ConfigServer eXploit Scanner (cxs)

It can reduce many bad scripts, but my question is this:

what if people try to upload fake sites, phishing scripts, botnet controllers, shells. The CXS will detect these? (Config server said that some of these yes.) And if yes, i assume scammers will tweak their scripts by encoding it getting away from the radar and i will have very low possibility to detect it? (Config server says CXS can decode files) Any experience regarding real usefullnes of the CXS and similar product and if bad users will adapt to go around it? CXS is claimed it can be set to search custom list of phrasses in files.

PS: alternative to CXS is said to be LMD/Maldet (no WHM interface):
Linux Malware Detect - R-fx Networks
GitHub - rfxn/linux-malware-detect: Linux Malware Detection (LMD)
 

quizknows

Well-Known Member
Oct 20, 2009
1,008
87
78
cPanel Access Level
DataCenter Provider
Honestly I have pretty good luck with CXS. Maldet I have mixed feelings about, and its modsecurity integration is horribly broken. The CXS modsecurity hook works pretty well and quickly, and overall I've been very happy with CXS detection rates.
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,909
2,225
463
Hello,

You can find additional user-feedback on both CXS and Maldet by searching for those terms using this forum's search feature.

Thank you.