Control Web Panel
Other => Other => Topic started by: cgauthey on July 06, 2026, 02:58:58 PM
-
Hello, I think my server has been compromised by a backdoor.
Yanz Webshell! - PRIV8 WEB SHELL ORB YANZ BYPASS! V3.0
The file READ-THIS-TO-RECOVER-YOUR-FILE.TXT
along with many other files—how do I fix these backdoors?
-
Well, sorry to say that you are the first known victim: https://forum.centos-webpanel.com/centos-webpanel-bugs/cwp-new-security-issue-and-no-communication
-
Well, sorry to say that you are the first known victim: https://forum.centos-webpanel.com/centos-webpanel-bugs/cwp-new-security-issue-and-no-communication
Don't mislead users. The links you provided point to pages describing vulnerabilities that affect Control Web Panel versions earlier than 0.9.8.1225.
The current CWP version is 0.9.8.1243.
So what's your point?
If you choose not to keep your system up to date, that's your responsibility. Also, just because a server was compromised doesn't mean it was hacked through a vulnerability in the control panel. The actual cause could just as easily be Joomla, WordPress, or some other software installed by the user. Don't you think that's a more reasonable assumption?
You're making a lot of noise.
-
@cyberspace
Please, don't try to deflect the issue - and even worst, try to deflect that issue to the users.
The vulnerability, before being patched, was active and was capable of being exploited... In true, that doesn't mean that THIS particular issue in this topic WAS because of this, but is just too much coincidence.
Lets just remember that there WAS another critical security issue in CWP, that WAS exploited, with multiple servers hacked... and we still don't have ANY info from the dev team about what happend... not even "sorry".
Even if is currently patched, that doesn't mean that some servers didn't get exploited BEFORE the patch was issued...
-
Any software has vulnerabilities. Some of them live more than 10 years: glibc: GHOST, Shellshock... etc.
That is why it is critically important to update all software but it doesn't make your system 100% safe.
-
Yes, every software can and will have vulnerabilities...
... but most of them notify the users about it and NOT silently patch the issue.
ALL the software that you stated, every single one of them... there WAS a statement from the developers about the issue.
Do you have ANY security fix statement from CWP dev team? to ANY vulnerability?
-
There were statements because openssl and glibc are life critical libs. They are used by bank systems, government, etc.
cPanel doesn't make statements about every vulnerabilities.
cPanel made statements about the vulnerabilities discovered in May because there were more than 40k hacked cPanel servers.
-
If you like cPanel and the price $40+ /month is acceptable for you then use cPanel and stop spamming this forum.
-
But the sky is falling... you're aware of that, right? The sky is falling! The sky is falling!
-
@cgauthey Keep your AL8 server updated and don't allow shell access to users and you'll be fine.
If you're still running CentOS 7, there are no patches for an EOL OS.
Yanz Webshell has been hitting Linux Kernels and WordPress sites.
CWP fixed this CVE several versions back.
But other software, like mentioned above may still have it, if you haven't updated and secured your server.