Live data from Hacker News

CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

copahost.com

81–83 of 83 posts

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#81
post #61
post #55

Earlier quoted context omitted.

This is not a PHP language interpreter bug this is a PHP FPM bug.

That's a fair point, using 'interpreter' specifically was imprecise language on my part. My main point was php-fpm is developed by the core PHP team and is often the default in how PHP projects deploy these days, and that CVE was very similar to the recent 'fail' LPE vulnerabilities in the kernel.

php-mod is so fast these days

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#82
post #79

We've been running Centminmod on our servers for years. Love the software. There is no fancy web UI but it does have CLI menus, etc... so, definitely not for the novice but it's really good at what it does. I'm not affiliated, just a happy customer: https://centminmod.com/

I love Centminmod but some of our clients need a UI so we settled on a mix of https://hestiacp.com/ and https://www.cloudpanel.io/

Re: CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers

#83
post #7

Ages ago I used php-nuke to manage my forum and it got hacked and I thought it would get taken seriously Seeing these CPanel hacks remind me how old these codebases are and how much more vulnerability remain

Cpanel is Perl, not PHP. Probably the grayest of the gray beards. Perhaps not enough Perl Wizards left to maintain it nowadays.

well, any accounts running outdated workloads (could be anything LAMP-flavored) could be attack vectors, with the entire shared machine possibly compromised by any weak account due to these latest LPEs

these cPanel machines frequently run 4- or low-5-figure quantities of customer accounts, each with potentially multiple domains or CMS deployments, and not always the most technically-engaged customer base, so that's a lot of surface area to account for: how diligent can hosts realistically be about every WordPress plugin, every Drupal or Magento module, and so on?

(nb I don't like shared hosting and am not defending it, just addressing the reality of the long tail)

Post reply on HN