Live data from Hacker News

CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

copahost.com

41–50 of 83 posts

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#41
post #16

Earlier quoted context omitted.

These PHP systems be it cPanel, wordpress or PHP itself are most likely the biggest target besides windows. It's incredibly uncool stack especially here but it is running most of the "independent" small web. They cannot be that bad if they are managing to be ductape of the internet.

Every time I venture in the the web server's error log, I see all of the skiddie's attempts at accessing the most common things with most of them being .php files. Lots of /wp/admin.php and /phpadmin/ type requests. Of course, none of those are available which is why the requests are in the error log. I've never paid attention, but I wonder how long (as in how little time) for a new server to come online before it st…

Dismissing these as script kiddie attempts is no longer correct. This is a real industry now. It’s not like the large scale actors are going to pass up a valid unpatched vector just because it’s old hat.

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#42

CPanel and hosters who use them are in big trouble now; there are millions of servers running them, many of them for decades. Their clients can run code as an user without much sandboxing/guardrails at all.

But those are updated automatically. It's unlike Windows or Linux, where the user decides when to update. cPanel updates are decided by cPanel

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#43
post #27
post #16

Earlier quoted context omitted.

These PHP systems be it cPanel, wordpress or PHP itself are most likely the biggest target besides windows. It's incredibly uncool stack especially here but it is running most of the "independent" small web. They cannot be that bad if they are managing to be ductape of the internet.

I've done PHP development for over 20 years, including some pretty large projects. I've never had a situation where a security flaw in PHP itself forced me to scramble to patch something before it got hacked. On the other hand, for my Linux servers, I had to do that twice in the last month with CopyFail and DirtyFrag.

[dead]

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#45

Earlier quoted context omitted.

Every time I venture in the the web server's error log, I see all of the skiddie's attempts at accessing the most common things with most of them being .php files. Lots of /wp/admin.php and /phpadmin/ type requests. Of course, none of those are available which is why the requests are in the error log. I've never paid attention, but I wonder how long (as in how little time) for a new server to come online before it st…

Dismissing these as script kiddie attempts is no longer correct. This is a real industry now. It’s not like the large scale actors are going to pass up a valid unpatched vector just because it’s old hat.

yes, but how often otherwise would i get to use the word skiddie?

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#46
post #35

Friendly reminder that there aren't that many ways for a normie to create their own (sub)domain with TLS and an email in under five minutes. That's cPanel for ya.

Yes, there are many ways to do that now, in under 5 minutes. Cloudflare will set all of that up just fine. GSuite is much easier to set up than CPanel.

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#48
post #7

Ages ago I used php-nuke to manage my forum and it got hacked and I thought it would get taken seriously Seeing these CPanel hacks remind me how old these codebases are and how much more vulnerability remain

I don't agree that "old" necessarily implies vulnerability.

As a coder who just hit 50, trust me, it does.

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#50
post #12

Earlier quoted context omitted.

[flagged]

Remember 'webmin'? As someone who pretty much exclusively uses debian, freebsd and openbsd for server OS work, I was also rather surprised recently to see the default web gui that comes on a new fedora install. https://cockpit-project.org/

Also comes default on Red Hat Enterprise Linux, Rocky Linux , AlmaLinux, Oracle Linux, and SUSE.

Also walrus from old, old UBNT forum? If so, hello :)

Post reply on HN