Earlier quoted context omitted.
These PHP systems be it cPanel, wordpress or PHP itself are most likely the biggest target besides windows. It's incredibly uncool stack especially here but it is running most of the "independent" small web. They cannot be that bad if they are managing to be ductape of the internet.
Every time I venture in the the web server's error log, I see all of the skiddie's attempts at accessing the most common things with most of them being .php files. Lots of /wp/admin.php and /phpadmin/ type requests. Of course, none of those are available which is why the requests are in the error log. I've never paid attention, but I wonder how long (as in how little time) for a new server to come online before it st…
CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
41–50 of 83 posts
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#42CPanel and hosters who use them are in big trouble now; there are millions of servers running them, many of them for decades. Their clients can run code as an user without much sandboxing/guardrails at all.
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#43Earlier quoted context omitted.
These PHP systems be it cPanel, wordpress or PHP itself are most likely the biggest target besides windows. It's incredibly uncool stack especially here but it is running most of the "independent" small web. They cannot be that bad if they are managing to be ductape of the internet.
I've done PHP development for over 20 years, including some pretty large projects. I've never had a situation where a security flaw in PHP itself forced me to scramble to patch something before it got hacked. On the other hand, for my Linux servers, I had to do that twice in the last month with CopyFail and DirtyFrag.
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#44People are still using cpanel?
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#45Earlier quoted context omitted.
Every time I venture in the the web server's error log, I see all of the skiddie's attempts at accessing the most common things with most of them being .php files. Lots of /wp/admin.php and /phpadmin/ type requests. Of course, none of those are available which is why the requests are in the error log. I've never paid attention, but I wonder how long (as in how little time) for a new server to come online before it st…
Dismissing these as script kiddie attempts is no longer correct. This is a real industry now. It’s not like the large scale actors are going to pass up a valid unpatched vector just because it’s old hat.
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#46Friendly reminder that there aren't that many ways for a normie to create their own (sub)domain with TLS and an email in under five minutes. That's cPanel for ya.
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#47CPanel and hosters who use them are in big trouble now; there are millions of servers running them, many of them for decades. Their clients can run code as an user without much sandboxing/guardrails at all.
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#48Ages ago I used php-nuke to manage my forum and it got hacked and I thought it would get taken seriously Seeing these CPanel hacks remind me how old these codebases are and how much more vulnerability remain
I don't agree that "old" necessarily implies vulnerability.
Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#49Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
#50Earlier quoted context omitted.
[flagged]
Remember 'webmin'? As someone who pretty much exclusively uses debian, freebsd and openbsd for server OS work, I was also rather surprised recently to see the default web gui that comes on a new fedora install. https://cockpit-project.org/
Also walrus from old, old UBNT forum? If so, hello :)