Author Topic: To the CWP team and all its users (We are tired of getting hacked every day.)  (Read 246 times)

0 Members and 1 Guest are viewing this topic.

Offline
*
To the CWP team and all its users:

For months, our servers have been under constant attack. All sites hosted on our servers are being redirected to gambling sites. They are ruining our SEO efforts; our sites' Google indices now contain tags related to gambling sites.

Cryptocurrency mining services are constantly being run on our servers.

While we can only access our servers using our root passwords, unauthorized individuals are gaining root access without needing any password and doing whatever they please on our systems.

We are losing all our customers; we spend 24/7 trying to repair the damage done to our servers. We simply no longer have the strength to keep doing this.

We format our servers and reinstall the operating system and the latest version of CWP, yet the servers get hacked again within the very same day.

I believe the CWP team fails to detect—and therefore cannot patch—security vulnerabilities, and that they lack personnel with the necessary expertise to properly develop or secure the panel.

For this reason, I want the CWP team to acknowledge these shortcomings and announce that they are ceasing development of CWP.

This would ensure everyone is informed, as many people are unaware that CWP has become nothing more than a "toy"—a system so insecure that even children can hack it and anyone can gain server access by any means.

Online
****
Hi,

Install CSF:
https://github.com/Aetherinox/csf-firewall
https://github.com/Black-HOST/csf
or similar firewall fork on your server and block access to the port 2304 for everyone except your billing server. If you don't need access to the CWP's API then leave the port 2304 closed.

Offline
*
Hi everyone, what’s going on here? This topic seems to have been kept under wraps by the "admins" and the CWP team—who I’m convinced are monitoring the forum but staying silent! Since version 1.12, there hasn't been any news regarding changes made in current versions.

Just security issues—problems that were reported as far back as last year.

What do you expect when CWP Panel relies on such outdated stacks? (PHP 5.6, Roundcube 1.5, Nginx, Apache, MariaDB 10.5, and so on)—these are the services the panel installs by default on AlmaLinux 8, the distribution recommended on the official site.

We know nothing about the CWP team; what work is actually being done on this panel? How can we continue to support it without receiving clear information about what's happening behind the scenes?

Since nothing is being announced, I’m starting to think CWP is obsolete—a dead project. I work with other panels too—DirectAdmin, HestiaCP, Pannelica, and KeyHelp—and when you install any of them, they come with PHP 8.5 and the latest versions of all services (helping us avoid CVEs, or allowing for quick updates when a new one drops).

With CWP, if I want to upgrade Roundcube, MariaDB, Nginx, or Apache, I run into a heap of errors. Am I supposed to hunt down forum scripts created by Sandeep B, overseer, or Starburst? Where is the CWP team?

Offline
*****
At it's core, I agree with you sentiment about the basic software stack. But it sounds as if you would be happier with another panel, so probably best if you switched. CWP seems to be geared more toward the DIY system admin and is a budget-conscious panel. For me it is the perfect mix of features and cost. I for one can't afford a panel that costs 10x more annually -- my servers would not be a going concern at that point. Now that I am intimately familiar with CWP after 5 years of use, I can manage CWP servers with the resources available (the wiki, this forum, AWS Monster, AlphaGNU).

Offline
*****
Those 'security issues' or CVE's where fixed last year, well before even CWP 1.x, and are getting old having to repost that same info over, and over, and over again...

Same as that BS about CWP being 'obsolete' and/or 'a dead project'.

CWP just released 1.18 on 2026-10-07, so if a 2 day old update is 'obsolete' or a a 'dead project', maybe goto cPanel...

If you have CWP Properly configured ON AL8 or AL9 with ModSecurity Properly configured and running, and CSF Properly configured and running there are no problems.
Which is easy, IF you are a trained system administrator.

Problem are with the EOL CentOS 7 OS, which is outside CWP's control.

CVE's can be found at:
https://sysadmin.help/viewforum.php?f=42

or goto:
https://www.cve.org/

Info is easy to find on alphagnu.com and starburst.help

FYI AlmaLinux 9 just release allot of system updates today, including for BIND, OpenSSL, ImageMagick.
AL9 released OpenSSH on 2026-10-04 to fix CVE's.
Not to mention all of the Kernel updates Linux has been pumping out for CVE's.

Offline
*****
At it's core, I agree with you sentiment about the basic software stack. But it sounds as if you would be happier with another panel, so probably best if you switched. CWP seems to be geared more toward the DIY system admin and is a budget-conscious panel. For me it is the perfect mix of features and cost. I for one can't afford a panel that costs 10x more annually -- my servers would not be a going concern at that point. Now that I am intimately familiar with CWP after 5 years of use, I can manage CWP servers with the resources available (the wiki, this forum, AWS Monster, AlphaGNU).

Aw man, I lost your love for starburst.help?