CPanel and hosters who use them are in big trouble now; there are millions of servers running them, many of them for decades. Their clients can run code as an user without much sandboxing/guardrails at all.
CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
11–20 of 83 posts
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#12Ages ago I used php-nuke to manage my forum and it got hacked and I thought it would get taken seriously Seeing these CPanel hacks remind me how old these codebases are and how much more vulnerability remain
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#13People are still using cpanel?
There are a lot of things that have been up for decades. The ROI on moving a simple PHP or static website to new hosting situation hasn’t been that compelling… though that could change. Thing is, I suspect most users of shared hosting which is Cpanel’s bread and butter are not reading the latest cybersecurity news.
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#14Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#15Ages ago I used php-nuke to manage my forum and it got hacked and I thought it would get taken seriously Seeing these CPanel hacks remind me how old these codebases are and how much more vulnerability remain
I don't agree that "old" necessarily implies vulnerability.
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#16Earlier quoted context omitted.
I don't agree that "old" necessarily implies vulnerability.
I mostly disagree on your disagreement unless the entire project was based on top security practices and good code in the first place. The vast majority of these web panels are a security nightmare.
They cannot be that bad if they are managing to be ductape of the internet.
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#17CPanel and hosters who use them are in big trouble now; there are millions of servers running them, many of them for decades. Their clients can run code as an user without much sandboxing/guardrails at all.
Such a different era.
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#18Earlier quoted context omitted.
Most shared hosting plans use cpanel. It's still widely used yes for a lot of smaller websites.
I wonder how much shared hosting is there really left, I imagine much of it move to VPS or cheap cloud boxes.
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#19Earlier quoted context omitted.
I mostly disagree on your disagreement unless the entire project was based on top security practices and good code in the first place. The vast majority of these web panels are a security nightmare.
These PHP systems be it cPanel, wordpress or PHP itself are most likely the biggest target besides windows. It's incredibly uncool stack especially here but it is running most of the "independent" small web. They cannot be that bad if they are managing to be ductape of the internet.
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#20Earlier quoted context omitted.
I mostly disagree on your disagreement unless the entire project was based on top security practices and good code in the first place. The vast majority of these web panels are a security nightmare.
These PHP systems be it cPanel, wordpress or PHP itself are most likely the biggest target besides windows. It's incredibly uncool stack especially here but it is running most of the "independent" small web. They cannot be that bad if they are managing to be ductape of the internet.
I think there are just a whole lot of tools written for them. So non devs can spin things up and click some things together.
Is that safe and secure? Maybe, if the devs did their work well. But I'm positive no one reads the docs on how to configure something securely.
I think the real reason is that it's very cheap to host, and always has been