Control Web Panel
WebPanel => How to => Topic started by: driftwood on May 09, 2016, 02:43:30 PM
-
While trying to find and fix an exploit I've managed to really mess up my access to my server. I stopped all the services except web & mysql and for some reason I managed to reboot my VPS in that state. Now I can not log in via CWP or via terminal.
I'm left with only the main domain site working and all the other sites inaccessible. Can anyone help ? I've sent a support request in as I'm willing to pay but I've not heard anything yet.
BWT - I noticed the auto Wordpress updates where sending me false reports that my WP installations had been updated to the latest version. I noticed this as suddenly I started getting failed emails that were in fact spam being sent out from my server.
-
you can ask host for this issue
-
My host is dragging their feet on this so no it looks like I'm going to have trash the server and do re-install. Luckily I can acess simple Ftp and mysqladmin to do the exports of the sites.
-
did you able to see the login screen in ssh ?
-
No, I think ssh is not running.
-
Try to connect ssh with different Ip or use any free vpn
If you succefully logged in then reset the csf firewall.
-
I have a VPN but currently login to the terminal from anywhere. I've actually decided to move the websites to my other server and cancel that hosting. I know it was my fault but expected a lot more interest from the support staff there. Doing nothing is worse then just saying we can't help.
-
Well that's annoying.
After no response from my host I decided to move all the sites to my other server. I shut down this server to stop all the spam email filling the mailqueue. I've now done that so I restarted the server and incredibly I can log into to CWP now. The are 298,722 emails in the mailqueue :-)
If you are using wordpress I suggest you do a search for these files
60dir.php s151.02kb
mail.php 11.36kb
mysql.php 28.11kb
dir24.php 11.19kb
list.php
These are also a valid filenames so view the contents before delete. Most the time they get in the /images of any subdir or the /uploads