Live data from Hacker News

CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

copahost.com

21–30 of 83 posts

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#21

People are still using cpanel?

Most shared hosting plans use cpanel. It's still widely used yes for a lot of smaller websites.

And even if it doesn’t look like it chances are it still is with a fancier ui on top.

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#22
post #16
post #15

Earlier quoted context omitted.

I mostly disagree on your disagreement unless the entire project was based on top security practices and good code in the first place. The vast majority of these web panels are a security nightmare.

These PHP systems be it cPanel, wordpress or PHP itself are most likely the biggest target besides windows. It's incredibly uncool stack especially here but it is running most of the "independent" small web. They cannot be that bad if they are managing to be ductape of the internet.

cPanel is Perl.

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#23

CPanel and hosters who use them are in big trouble now; there are millions of servers running them, many of them for decades. Their clients can run code as an user without much sandboxing/guardrails at all.

Such a different era.

I miss this era, we overcomplicated everything

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#24
post #10

Earlier quoted context omitted.

Half of the entire internet is Meta properties.

That’s the other half. Coincidentally also PHP.

Facebook started out PHP; but they ship-of-theseus'ed it into Hack by replacing the standard library, the language, and the runtime engine, so now it's a totally different thing with only a few superficial similarities (FWIW IMO Hack is much better than PHP, I'm sad that it never gained traction...)

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#25
post #16

Earlier quoted context omitted.

These PHP systems be it cPanel, wordpress or PHP itself are most likely the biggest target besides windows. It's incredibly uncool stack especially here but it is running most of the "independent" small web. They cannot be that bad if they are managing to be ductape of the internet.

How does that follow?

They have a big target on their back so the low hanging fruit is (mostly) gone.

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#26
post #12
post #7

Ages ago I used php-nuke to manage my forum and it got hacked and I thought it would get taken seriously Seeing these CPanel hacks remind me how old these codebases are and how much more vulnerability remain

[flagged]

Of course is the architecture and the creator of such a thing, isn’t the point of a tool like that for users that don’t have the tech knowledge? I have only used those systems on shared hosting, host providers are the one maintaining and should be keeping them up to date and WHM/Cpnel have plenty of customers to worry too patch holes, if they can’t then who’s fault is it, Architecture, or provider? Hope is the customers fault?

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#27
post #16
post #15

Earlier quoted context omitted.

I mostly disagree on your disagreement unless the entire project was based on top security practices and good code in the first place. The vast majority of these web panels are a security nightmare.

These PHP systems be it cPanel, wordpress or PHP itself are most likely the biggest target besides windows. It's incredibly uncool stack especially here but it is running most of the "independent" small web. They cannot be that bad if they are managing to be ductape of the internet.

I've done PHP development for over 20 years, including some pretty large projects. I've never had a situation where a security flaw in PHP itself forced me to scramble to patch something before it got hacked.

On the other hand, for my Linux servers, I had to do that twice in the last month with CopyFail and DirtyFrag.

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#28
post #24
post #10

Earlier quoted context omitted.

That’s the other half. Coincidentally also PHP.

Facebook started out PHP; but they ship-of-theseus'ed it into Hack by replacing the standard library, the language, and the runtime engine, so now it's a totally different thing with only a few superficial similarities (FWIW IMO Hack is much better than PHP, I'm sad that it never gained traction...)

Much of what was good in Hack just got rolled into PHP.
Post reply on HN